genai
SECURITY LAB
Legal

Security Policy

Last updated August 17, 2026

How we protect the platform, and how to report a vulnerability in GenAI Security Lab itself.

How we protect the platform

  • Lab targets run in isolated, ephemeral sandboxes torn down after each session.
  • Each learner receives session-specific, randomized secrets, so answers are not shared between users.
  • Data is encrypted in transit and at rest; access to production is least-privilege and logged.
  • We maintain an internal audit log of administrative actions for accountability.

Reporting a vulnerability

If you discover a security issue in the GenAI Security Lab platform — as opposed to the intentionally vulnerable lab targets — email [email protected] with enough detail to reproduce it. Please do not publicly disclose it until we have had a reasonable opportunity to fix it.

We will acknowledge your report, keep you updated, and credit you if you wish. We will not pursue good-faith researchers who follow this policy.

Scope

In scope: the platform, accounts, billing, and infrastructure. Out of scope: the deliberately vulnerable targets in the labs (breaking those is the point) and findings that require attacking other users.