Security

Vulnerability Disclosure Program

Last updated: June 17, 2026

Easentic takes the security of our platform and our customers’ data seriously. We welcome reports from security researchers and the public, and we are committed to working with you to verify, reproduce, and resolve valid issues. This page explains what is in scope, how to report a vulnerability, and what you can expect from us.

1. Scope

This program covers the systems Easentic operates, including:

  • The Easentic Slack app (Elisa) and its install and event handling
  • The Easentic web application at app.easentic.ai
  • The Easentic marketing site at www.easentic.ai
  • Easentic’s public APIs and webhook endpoints

Out of scope. Please do not test or report issues in third-party services Easentic integrates with — including Atlassian Jira, ClickUp, Google (Calendar/Meet/Vertex AI), Recall.ai, OpenAI, and Google Cloud infrastructure. Report those directly to the respective vendor. Vulnerabilities in how Easentic handles those integrations are in scope.

Also out of scope: denial-of-service (DoS/DDoS) and volumetric/resource-exhaustion attacks; social engineering or phishing of Easentic staff, customers, or vendors; physical attacks; reports from automated scanners without a demonstrated, exploitable impact; and issues that require an already-compromised account or device.

2. How to report

Email security@easentic.ai with:

  • A description of the issue and its potential impact
  • Clear steps to reproduce
  • Any proof-of-concept code, requests, or screenshots
  • Your name or handle and contact details so we can follow up (and how you’d like to be credited)

Please send one issue per report. If a report contains sensitive data, tell us and we will arrange a secure channel.

3. Safe harbor

We consider security research and vulnerability disclosure conducted in good faith and in accordance with this policy to be authorized. We will not pursue or support legal action against, and will not otherwise retaliate against, researchers who act in good faith and:

  • Make a genuine effort to avoid privacy violations, data destruction, and service disruption
  • Only access, store, or disclose the minimum data necessary to demonstrate the issue
  • Do not access, modify, or delete data belonging to other users
  • Stop testing and notify us immediately if they encounter user data, and do not retain it
  • Give us reasonable time to remediate before any public disclosure (see §5)

If legal action is initiated by a third party against you for activity that complied with this policy, we will make this authorization known. This policy does not authorize actions that violate applicable law.

4. What you can expect from us

  • We will acknowledge your report within 2 business days.
  • We will keep you updated as we investigate and remediate.
  • With your permission, we will credit you in our security advisories.
  • We do not currently operate a paid bug-bounty program, but we deeply appreciate responsible disclosure and recognize valid reports.

5. Coordinated disclosure

Please coordinate with us before any public disclosure. We ask for a 90-day window from your initial report to investigate and remediate. If an issue is being actively exploited, or remediation is substantially complete sooner, we can agree to a shorter timeline. We will work with you on disclosure timing and will not ask for indefinite secrecy.

6. Contact

Security reports: security@easentic.ai. For general support, see easentic.ai/contact. To report a suspected compromise of your own Easentic account, email security@easentic.ai immediately with the subject line URGENT.