Effective: 2026-09-06
Effective date: 2026-09-06 · Version: 1.2.0 · Last updated: 2026-09-06
Security is foundational to Aidealy. We build the Service around protecting our customers' most sensitive asset - their source code, their developers' work, and the people behind it - and we welcome the work of security researchers who help us keep it safe.
This Vulnerability Disclosure Policy (the "Policy") explains how to report a security vulnerability you believe you have found in Aidealy, what you can expect from us in return, and the rules that keep your research lawful and safe for everyone. It applies to Aidealy Ltd. ("Aidealy", "we", "us"), the company behind the Aidealy product and website.
This is a coordinated vulnerability disclosure program, modelled on the recognised international practice for receiving and handling vulnerability reports (ISO/IEC 29147 and ISO/IEC 30111) and on the guidance of national cybersecurity authorities. It is not a paid bug-bounty program - see §9 (Recognition).
This Policy applies to the systems Aidealy operates and controls:
| In scope | Notes |
|---|---|
The Aidealy website - aidealy.ai and *.aidealy.ai | The marketing site and its subdomains |
| The Aidealy Service - the web application (admin and chat) | The product you sign in to |
| The Aidealy IDE extension - the VS Code / Cursor extension | Both regional editions |
| The Aidealy Claude Code collector - the standalone program installed on developers' machines | Including its installer and its update mechanism |
The following are out of scope, and testing them is not authorised by this Policy:
Reports limited to the following, without a demonstrated, realistic security impact, will usually be acknowledged but not treated as actionable vulnerabilities: missing security headers or cookie flags; output of automated scanners without a working proof of concept; absence of rate-limiting where no concrete abuse is shown; theoretical or best-practice issues; reports about software versions alone; and self-inflicted issues (e.g. requiring a fully compromised device or a man-in-the-middle you control).
Email your report to security@aidealy.ai.
security.txt file at https://aidealy.ai/.well-known/security.txt (per RFC 9116).We want you to be able to do good-faith security research without fear of legal consequences. When you make a good-faith effort to comply with this Policy, then with respect to systems within scope (§2):
"Good faith" means, in line with recognised standards: you access only what you need to identify and demonstrate a vulnerability; you avoid harm to people, to data, and to the availability of the Service; you do not use, retain, or disclose data you encounter beyond what is necessary to report; and your purpose is to improve security, not to extort, defraud, or benefit improperly. Activity that is not in good faith - for example, using a "research" label to cover extortion - is not protected by this Policy.
Limits of this safe harbor - please read. We can only speak for ourselves. This Policy:
If a third party brings a claim against you for activity that complied with this Policy, we will, where we lawfully can, take reasonable steps to make clear that your activity was authorised by us.
To help us triage and reproduce the issue quickly, please include where you can:
Because the Service processes highly sensitive customer data - source code, AI prompts and responses, and personal data - these rules are conditions of the authorisation and safe harbor in §4. When testing, you must:
When you report in line with this Policy, we will:
Regulatory reporting (EU Cyber Resilience Act). Separately from the commitments above, we assess every reported vulnerability against the reporting triggers of the EU Cyber Resilience Act (Regulation (EU) 2024/2847). Where a vulnerability in the Aidealy IDE extension or in the Aidealy Claude Code collector (in each case including the Aidealy backend services that software depends on to work) is being actively exploited, or a severe incident impacts the product's security, Aidealy reports it - as the Act requires from 11 September 2026 for software made available in the EU, including versions already on the market - to the designated national CSIRT coordinator and to ENISA through the EU's single reporting platform: an early warning within 24 hours of our becoming aware, a fuller notification within 72 hours, and a final report on the Act's timeline. Where the Act requires it, we also inform impacted users of the vulnerability or incident and of available corrective or mitigating measures. These are Aidealy's own regulatory duties to the authorities: they operate alongside - and do not change - the acknowledgement and handling commitments made to reporters in this section.
We follow a coordinated disclosure approach: we ask that you give us a reasonable opportunity to remediate a reported vulnerability before you disclose it publicly or to any third party.
Aidealy does not currently operate a paid bug-bounty program, and this Policy makes no offer of monetary reward and no formal public-recognition ("hall of fame") commitment. By submitting a report you agree that you are not entitled to compensation for it.
We are genuinely grateful for responsible reports, and may, at our discretion, thank or publicly credit a researcher whose report we act on - but we do not promise to do so.
If, despite the rules in §6, your research involves personal data, you must handle it consistently with this Policy and applicable data-protection law, and must not retain or further process it. How Aidealy itself handles personal data is described in our Privacy Policy and, for customer work data, our Data Processing Agreement; our broader security posture is described on our Security & Trust page. This Policy should be read alongside our Terms of Service and Acceptable Use Policy.
This Policy covers security vulnerabilities. If your concern is instead about how Aidealy develops or uses AI - for example the fairness of AI-assisted evaluations - rather than a security vulnerability, please write to ai-concerns@aidealy.ai. The AI-concerns channel is separate from this Policy, which continues to cover security vulnerabilities only.
We may update this Policy from time to time as our practice and the legal landscape evolve. The version and "last updated" date at the top reflect the current version. Operating coordinated vulnerability disclosure is good security practice that EU cybersecurity law encourages (such as the NIS2 framework's coordinated-disclosure provisions) - and, in part, now requires: from 11 September 2026 the EU Cyber Resilience Act's vulnerability and incident reporting duties described in §7 apply to the Aidealy IDE extension and, from the day it is first made available to customers in the EU, to the Aidealy Claude Code collector, and the Act's remaining vulnerability-handling requirements - including a formal coordinated vulnerability disclosure policy and a stated support period - apply to products placed on the market from 11 December 2027.
Aidealy Ltd.
security@aidealy.ai
Hamidron 1
Herzliya 4654110
Israel