Skip to main content
AI Policy File

Security

Current architecture

The public checker runs locally in the browser and the site has no public user accounts, saved checker-result database, billing system, or general-purpose product or data API. It does expose a narrowly validated founding-list submission endpoint. This smaller data surface reduces risk but does not eliminate it. Founding-list processing and analytics are described in the Privacy Policy.

Technical safeguards

  • HTTPS with strict transport security and restrictive browser security headers.
  • Server-side environment variables for service credentials; secrets are not placed in client code.
  • Same-origin, size, field, and consent checks on the founding-list endpoint.
  • Automated dependency, code-quality, and static security scanning in the release workflow.
  • Application logging designed to exclude checker answers and founding-list content.

Report a vulnerability

Send a concise report to hello@aipolicyfile.com. Include the affected URL, impact, reproduction steps, and a safe proof of concept. Do not access other people's data, disrupt the service, or send secrets in the report.

Incident priorities

Security, privacy, billing, availability, and legal-content integrity incidents are triaged separately. A wrong legal status, date, exception, checker rule, or citation is treated as a production integrity issue even when the software remains available.