Telos BrainLegal

    Vulnerability Disclosure Policy

    Last changed 20 August 2026

    Published by Telos Limited · Version 2.1 · Effective 20 August 2026

    In brief

    If you find a security vulnerability in Telos Brain, we want to hear about it. Report it to security@telosbrain.com. Test only what is in scope, do not access other people's data, and give us a reasonable chance to fix the issue before you talk about it publicly. If you follow this policy, we will not pursue legal action against you for your research.

    We do not currently operate a paid bug bounty.

    1. How to report

    1.1 Email security@telosbrain.com. Where possible, encrypt your report using the PGP key published at https://www.telosbrain.com/.well-known/security.txt.

    1.2 Please include:

    1. the affected product, URL, package version or endpoint;
    2. a clear description of the issue and its likely impact;
    3. the steps needed to reproduce it, including any proof-of-concept code;
    4. any account or identifier you used in testing; and
    5. how you would like to be credited, if at all.

    1.3 Report in English where you can. Report one issue per email.

    1.4 Do not report a vulnerability through a support ticket, a public issue tracker, social media, or by contacting an individual employee.

    2. What is in scope

    2.1 This policy is published by Telos Limited and covers the Telos Group. In scope:

    1. the Telos Brain cloud service and its APIs;
    2. the Telos Brain control plane, including account, authentication, entitlement and metering services;
    3. the Telos Brain command line interface and any package we publish to a public package registry;
    4. container images we publish;
    5. starter templates we publish;
    6. the telosbrain.com website; and
    7. the Telos Limited Trust Centre.

    2.2 Out of scope:

    1. a self-hosted deployment operated by a customer. You may test a deployment running in your own environment, but findings specific to a customer's configuration are that customer's responsibility, not ours. If you believe you have found a flaw in the software as we ship it, that is in scope and we want to know;
    2. systems operated by a model provider, cloud provider or other third party, even where Telos Brain connects to them. Report those to the operator concerned;
    3. a customer's data, Brain, or account;
    4. findings that require physical access to a device, or access to an already-compromised account or environment;
    5. social engineering of our staff, customers or suppliers, including phishing and pretexting;
    6. denial of service, resource exhaustion, and volumetric or brute-force testing;
    7. findings produced solely by an automated scanner without a demonstrated impact;
    8. missing security headers, cookie flags, TLS configuration preferences, or the absence of rate limiting, in each case without a demonstrated exploit;
    9. reports about software versions being out of date, without a demonstrated exploitable path;
    10. email configuration findings such as SPF, DKIM or DMARC, unless you can demonstrate practical exploitation; and
    11. self-XSS, clickjacking on pages with no sensitive action, and issues requiring an unlikely degree of user interaction.

    3. Rules of engagement

    3.1 When testing, you must:

    1. use only your own accounts, or accounts you have explicit permission to test;
    2. stop as soon as you have confirmed a vulnerability, and not go further than is necessary to demonstrate it;
    3. not access, modify, copy, retain, transmit or delete any data that is not yours;
    4. not degrade, disrupt or interrupt the service for anyone else;
    5. not use a finding to obtain anything of value, and not attempt to extort us;
    6. delete any data you obtained incidentally as soon as you have reported it, and confirm to us that you have; and
    7. comply with all applicable law.

    3.2 If you inadvertently access data that is not yours, stop immediately, do not look further, tell us in your report, and delete it.

    4. Safe harbour

    4.1 If you make a good faith effort to comply with this policy, we will:

    1. treat your research as authorised for the purposes of any applicable computer misuse law, including sections 249 and 252 of the Crimes Act 1961;
    2. not pursue or support any civil claim or criminal complaint against you in relation to that research;
    3. not treat it as a breach of the Telos Brain Terms of Use or the Acceptable Use Policy; and
    4. if a third party brings an action against you in relation to research conducted under this policy, take reasonable steps to make it known that your conduct was authorised.

    4.2 This safe harbour applies only to conduct within the scope in section 2 and the rules in section 3. It does not authorise you to breach the rights of any other person, and we cannot grant authorisation on behalf of a third party.

    4.3 If you are unsure whether something is in scope, ask us at security@telosbrain.com before you test it. We would much rather answer that question in advance.

    5. What you can expect from us

    5.1 Our targets:

    StageTargetNotes
    Acknowledgement of your report2 working daysAutomated receipt is not acknowledgement
    Initial triage and severity assessment5 working daysWe will tell you whether we accept the finding
    Progress updateEvery 14 daysUntil the issue is resolved or closed
    Remediation — critical and high30 daysOr a documented plan where that is not achievable
    Remediation — medium and low90 days
    Coordinated public disclosureBy agreementSee clause 6

    5.2 We will tell you if we decide not to act on a report, and why.

    5.3 We will treat your report confidentially and will not share your identity outside Telos without your consent, unless we are required to.

    6. Disclosure

    6.1 Please do not disclose a vulnerability publicly until we have had a reasonable opportunity to remedy it and we have agreed timing with you.

    6.2 We will work with you in good faith on coordinated disclosure. Our default position is that public disclosure is appropriate once a fix is available to affected users, or 90 days after your report, whichever is earlier.

    6.3 Where a vulnerability affects a version of the software that customers run themselves, we will publish an advisory and, where warranted, request a CVE identifier. Customers are contractually required to apply security updates within the period stated in the Telos Brain Terms of Use.

    6.4 With your permission, we will credit you in the advisory.

    7. Recognition

    7.1 We do not currently operate a paid bug bounty and do not offer monetary rewards.

    7.2 We maintain an acknowledgements page on the Telos Limited Trust Centre and will list researchers who report valid issues, unless you ask us not to.

    8. Changes

    8.1 We may update this policy. The version in force is the one published at https://trust.telosready.com. This policy is referred to in clause 4.2 of the Telos Brain Acceptable Use Policy.