Security
TunerStack Vulnerability Disclosure Policy
Effective date: August 6, 2026
YGT Labs AI LLC welcomes good-faith reports about security vulnerabilities in TunerStack websites, portals, desktop software, and public APIs. This policy describes the safe way to report a suspected issue and what a reporter can expect from us.
How to report
- Email [email protected] with the subject TunerStack Security Report.
- Include the affected URL or component, a concise description, reproduction steps, impact, and any supporting logs or screenshots that do not contain passwords, tokens, private keys, or customer data.
- If the report contains sensitive material, say so in the first message. Do not send live credentials or secrets by email.
Response and handling
We acknowledge a report within 72 hours, triage its severity and scope, and keep the reporter informed when a material update is available. We may request additional details, reproduce the issue in an isolated environment, and coordinate a remediation or disclosure timeline based on risk.
Safe-harbor expectations
Good-faith testing that avoids privacy violations, service disruption, data access beyond what is necessary to prove the issue, social engineering, spam, and physical attacks is welcome. Stop testing and contact us if you encounter personal data or credentials. We will not pursue legal action for authorized, good-faith research that follows this policy and does not bypass these limits.
Out of scope
- Denial-of-service, load testing, spam, social engineering, phishing, or physical attacks.
- Reports based only on missing security headers or version banners without a demonstrated security impact.
- Issues in third-party services that are not operated by YGT Labs AI LLC.
Contact
YGT Labs AI LLC
Email: [email protected]