Skip to main content
← Security

Disclosure policy

Tessera welcomes responsible disclosure from security researchers. We do not have a paid bounty program at this stage, но recognize contributions publicly (with permission).

In scope

Out of scope

Process

  1. Email security@tesseraai.io with proof-of-concept + impact assessment
  2. We acknowledge within 48 hours
  3. We work toward a fix; estimated timeline shared within 7 days
  4. Coordinated public disclosure after fix deployed (90-day window default)

Safe harbour

Good-faith research conducted under this policy will not be subject to legal action by Tessera. Please act responsibly: do not access more data than necessary to demonstrate impact, do not destroy or modify data, и не disrupt service for others.

Contact: security@tesseraai.io