Skip to content
Get access

Legal

Disclosure policy

Effective 2026-09-19 · entity: Ledgerbook AI · coordinated vulnerability disclosure — security@ledgerbook.ai is the monitored channel and the policy currently in force (NFR-15).

How to report

Report suspected vulnerabilities to security@ledgerbook.ai — the address published in /.well-known/security.txt. Include what you found, the surface affected (site, API, MCP surface or deployment class) and reproduction steps you are willing to share. Encrypted reports are welcome; ask for a key in your first message.

What we commit to

We acknowledge reports, work with you on a fix window, and credit researchers who want to be named. We ask that you give us a reasonable window to remediate before public disclosure, and we will tell you what we are doing and when we expect to be done. We do not pursue researchers who report in good faith and stay within the scope below.

Scope

In scope: ledgerbook.ai and its machine surfaces (site, llms.txt, security.txt, published API and MCP contracts). Out of scope: third-party services we link to, social engineering, physical attacks, and self-hosted deployments operated by customers — those are theirs to run, and reports about a customer's configuration belong with that customer.

The extended policy

This page states the channel and the commitments that are true today. The extended policy — response windows, severity handling and the legal detail — ships with the developer preview and supersedes this page, with the change noted in the log below. Until then, the security page and security.txt are the policy of record.

Change log

  • 2026-09-19 — first publication (pre-launch: security.txt channel, scope and commitments; extended policy pending).