How we protect the platform, and how to report a vulnerability in GenAI Security Lab itself.
If you discover a security issue in the GenAI Security Lab platform — as opposed to the intentionally vulnerable lab targets — email [email protected] with enough detail to reproduce it. Please do not publicly disclose it until we have had a reasonable opportunity to fix it.
We will acknowledge your report, keep you updated, and credit you if you wish. We will not pursue good-faith researchers who follow this policy.
In scope: the platform, accounts, billing, and infrastructure. Out of scope: the deliberately vulnerable targets in the labs (breaking those is the point) and findings that require attacking other users.