Report privately
Email team@supertrained.ai with “Windlord security” in the subject. The canonical machine-readable contact is security.txt. Do not send passwords, OAuth tokens, session material, recovery phrases, private keys, payment details, or mailbox/calendar content.
What makes a report actionable
- affected Windlord component, URL, platform, and version/build;
- reproduction steps using synthetic data and your own account;
- expected and observed behavior;
- security impact and the minimum conditions required;
- approximate UTC time, content-free request/operation ID, and safe contact method;
- whether you believe exploitation is active or customer action is immediately needed.
Good-faith research and safe harbor
If you act in good faith, follow this policy, avoid privacy and service harm, and give us a reasonable opportunity to remediate before disclosure, Supertrained Inc. will not initiate legal action against you for the research. If a third party initiates action based on policy-compliant research, we will make our authorization of that research known.
This safe harbor applies only to claims we control and does not authorize violations of another provider’s terms, access to third-party data, or activity prohibited by law. If you are uncertain whether a test is safe, stop and ask before continuing.
Research limits
- Use only accounts and data you own or have explicit written permission to test.
- Stop immediately if you encounter another person’s data or gain unintended persistent authority; report what happened without copying or retaining the data.
- Do not perform denial of service, traffic flooding, destructive testing, social engineering, physical intrusion, malware deployment, credential stuffing, broad automated scanning, or supply-chain attacks.
- Do not execute a real email, calendar, agent, deletion, purchase, refund, or entitlement action against a third party.
- Do not degrade security controls, delete or alter data, pivot to another system, establish persistence, or exfiltrate more than the minimum synthetic proof.
- Do not test Google, Apple, Stripe, Firebase, Cloudflare, Microsoft, or another provider’s infrastructure under this policy.
Scope
In scope: production Windlord applications distributed by Supertrained Inc.; windlord.app and its documented production API; the local agent/MCP authority boundary; and Windlord-operated cloud services. Out of scope: third-party provider infrastructure, inactive prototypes, social engineering, employee devices/accounts, and findings that require a rooted/jailbroken device or disabled platform security unless they cross a separate Windlord trust boundary.
Examples we prioritize include unauthorized Gmail/Calendar or agent actions; authority/grant bypass; OAuth or device-identity confusion; receipt, reconciliation, or exact-once failures that misstate external effects; cross-account data access; cryptographic or protected-storage bypass; deletion resurrection; plaintext content reaching hosted analytics/control planes; and release/update trust failures.
What to expect from us
- automatic or human acknowledgement as soon as practical, with a private-beta target of one business day;
- initial triage and severity assessment, normally within three business days;
- a named contact and requests only for the minimum evidence needed;
- progress updates at meaningful milestones;
- coordination on remediation and disclosure timing;
- credit if you request it and disclosure is appropriate.
These are operational targets, not payment or bounty promises. Duplicate, non-security, purely theoretical, already-public, or policy-violating reports may receive a short closure response.
Coordinated disclosure
Do not publish exploit details before we have had a reasonable opportunity to validate, contain, remediate, distribute an update, and notify affected customers or providers. We will not use coordination as a pretext for indefinite silence: if remediation takes longer, we will discuss a risk-adjusted disclosure date and what can safely be shared.