Security disclosure policy

Coordinated vulnerability disclosure for Apex Platform (southlodge.ai). Filed 2026-05-07. RFC 9116 security.txt at /.well-known/security.txt.

How to report

Email security@southlodge.ai. Include:

Response SLAs

Stage Target What you'll receive
Acknowledgement 1 business day "Got it, we're triaging."
Initial triage + severity 3 business days Our severity assessment + an estimated remediation window.
Critical / High remediation 30 days Patch deployed; you'll get the commit hash.
Medium remediation 60 days Patch deployed; commit hash.
Low / informational 90 days or next minor release Tracked in our internal backlog.
Coordinated disclosure Negotiated; default 90 days post-fix Public credit, blog post if you'd like one.

Scope

In scope:

Out of scope:

Safe harbour

If you make a good-faith effort to comply with this policy during your security research, we will:

This protection applies only when you:

Acknowledgements

Researchers who follow this policy are listed on our Hall-of-Fame page under the handle they request. We're not yet running a paid bug-bounty programme — that's gated on customer-revenue milestones tracked in our HUMAN-DECISIONS register §3. We will write a public acknowledgement post for any Critical or High that's responsibly disclosed, with your handle if you want it.

What we won't do

What we ask you not to do

Versions

v1.0 — 2026-05-07. Filed at public/security/disclosure-policy.html in source. Markdown source at docs/security/disclosure-policy.md in source.