Bug Bounty & Responsible Disclosure
Last updated: August 3, 2026
Our approach
Content24 welcomes responsible disclosure from security researchers. If you believe you have found a security vulnerability, please report it to us before public disclosure.
We investigate valid reports in good faith and work to remediate confirmed issues according to severity.
In scope
- content24.ai and official subdomains operated by Content24
- The Content24 web application and authenticated API surfaces
- Official mobile or desktop clients if and when published by Content24
Out of scope
- Third-party services, integrations, or subprocessors not operated by Content24
- Social engineering, phishing, or physical attacks against staff or customers
- Denial-of-service or load tests without prior written approval
- Issues requiring unlikely user interaction or compromised end-user devices
- Scanner output without demonstrated exploitability
- Findings in deprecated or non-production environments clearly marked as such
Rules of engagement
- Do not access, modify, or delete data that is not your own.
- Do not disrupt service for other users.
- Give us reasonable time to investigate and fix before public disclosure (typically 90 days).
- Provide a clear reproduction steps and, if possible, proof-of-concept.
How to report
Email security@content24.ai with the subject line “Security report”. Include:
- Description of the vulnerability and potential impact
- Steps to reproduce
- Affected URL or component
- Your name and contact (optional — for recognition or follow-up)
Recognition
We do not operate a paid public bug bounty program at this time. With your permission, we may acknowledge researchers who report valid, previously unknown issues in a security advisory or hall of fame.
We may offer rewards at our discretion for exceptional reports — this is not a guarantee of payment.
Safe harbour
If you follow this policy in good faith, we will not pursue legal action against you for research activities that comply with these rules.
For general security practices and certifications, see our Security page.