Security
Last updated: September 24, 2026
How to report a security vulnerability in Rivul AI, what is in scope, and the limits to respect while testing.
How to report a vulnerability
Send security reports through the contact form at rivul.ai/contact and choose the topic Bug. No security mailbox, personal or otherwise, is published. The security.txt file at rivul.ai/.well-known/security.txt points to the same form.
Include the affected URL or route, the steps to reproduce the issue, and the impact you observed. Do not include other people's data.
What is in scope
In scope are rivul.ai and its API, as served by the current production deployment. Preview and local builds are not supported targets.
The most valuable reports concern anything that reads or writes another account's drafts, PDFs or library; authentication and session handling; and anything that lets one account spend another account's AI quota.
What is out of scope
Reports generated by a scanner with no demonstrated impact, missing headers with no exploit path, and denial of service by volume are out of scope.
Testing limits
Use your own account. Do not access other accounts' data or degrade the service.
Do not run automated scanners against production, and do not upload other people's unpublished manuscripts as test data.
After you report
Reports are read. There is no guaranteed response time. Please allow ninety days before publishing details of an issue.
There is no bug bounty programme, and there is no legal action for good-faith research.