Legal04 / 04

Security & Vulnerability Disclosure

Last updated · June 3, 2026 · v1.0
The short version

Found a security issue? Email security@boringaico.com. We welcome good-faith research and won't pursue legal action for testing that follows this policy. We aim to acknowledge reports within three business days.

01

Reporting a vulnerability

If you believe you've found a security vulnerability in Boring, please report it privately to security@boringaico.com. Include enough detail for us to reproduce the issue:

  • ·What you found — the vulnerability type and its impact.
  • ·Where — the affected URL, endpoint, or component (web app, agent runtime, public API, or an integration connector).
  • ·How to reproduce it — steps, a proof-of-concept, and any request/response details or screenshots.

Please give us a reasonable opportunity to fix the issue before disclosing it publicly, and don't access, modify, or delete data that isn't yours while testing.

02

Scope

This policy covers the systems we operate:

  • ·boringaico.com and the application, including the dashboard and authenticated APIs.
  • ·The agent runtime — agent execution, run logs, approvals, and stored memory.
  • ·The MCP API/api/mcp and its OAuth discovery endpoints.
  • ·Integration connectors — the OAuth grants and credentials linking agents to your tools.
03

Safe harbor

We consider security research and vulnerability disclosure conducted in good faith under this policy to be authorized. We will not pursue or support legal action against you for such research, provided you:

  • ·make a good-faith effort to avoid privacy violations, data destruction, and interruption or degradation of our service;
  • ·only interact with accounts you own or have explicit permission to access, and stop as soon as you've confirmed a vulnerability;
  • ·don't exfiltrate data, and report promptly without exploiting the issue further or disclosing it publicly before it's fixed.
04

What to expect

  • ·Acknowledgement within three business days of your report.
  • ·Triage & updates — we'll validate the issue, assess severity, and keep you informed.
  • ·Remediation — we prioritize fixes by severity and address critical issues as quickly as we can.
05

Out of scope

The following are generally out of scope. Reports limited to these will usually be closed without action:

  • ·volumetric or denial-of-service attacks, automated scanner output without a demonstrated impact, and spam or social-engineering of our staff or users;
  • ·missing best-practice headers, cookie flags, or rate limits with no concrete exploit; self-XSS; and clickjacking on pages with no sensitive action;
  • ·issues in third-party services we rely on (e.g. Cloudflare, model providers) — please report those to the respective vendor.
06

Recognition

Boring does not currently run a paid bug-bounty program. We're grateful for responsible disclosure and are happy to publicly credit researchers who report valid issues, if you'd like. A machine-readable version of this policy is available at /.well-known/security.txt.

Boring AI, Inc.legal@boringaico.comQuestions about your data? privacy@boringaico.com — we reply within 30 days.