Security
Vulnerability Disclosure Policy
Last Updated: September 10, 2026
Octane AI, Inc. ("Octane AI") builds quiz and personalization software used by online merchants. We process shopper and merchant data on their behalf, and we treat reports of security weaknesses as high-priority work. We welcome reports from security researchers, customers, and merchants, and we will not pursue legal action against researchers who follow this policy in good faith.
How to report a vulnerability
Please email security@octaneai.com. Include:
- A description of the vulnerability and its potential impact.
- Steps to reproduce, with request/response detail or a proof of concept.
- Affected URLs, endpoints, or components.
- Any relevant configuration (browser, OS, tooling).
- How you would like to be credited, if at all.
If you need to share sensitive material, ask us for our PGP key in your first message.
Our response commitments
- Acknowledgement of your report within 2 business days.
- Initial triage and severity assignment within 5 business days.
- Status updates at least every 10 business days while a report is open.
- Notification when the issue is resolved.
Remediation timelines by severity
We assign severity using CVSS v3.1, adjusted for exploitability in our environment and the sensitivity of the data at risk.
| Severity | CVSS v3.1 | Target remediation |
|---|---|---|
| Critical | 9.0–10.0 | Mitigation within 24 hours; permanent fix within 7 days |
| High | 7.0–8.9 | 30 days |
| Medium | 4.0–6.9 | 90 days |
| Low | 0.1–3.9 | 180 days, or documented as accepted risk |
For confirmed Critical findings we prioritize immediate mitigation (a feature flag, a WAF rule, or credential rotation) ahead of the permanent fix, so that any exposure ends as quickly as possible.
Scope
In scope:
- octaneai.com and app.octaneai.com, including the merchant dashboard.
- The Octane AI app, including its app proxy and storefront quiz embed.
- Our public APIs and webhook endpoints.
- Our authentication and session-handling flows.
Out of scope:
- The e-commerce platform's own infrastructure — report those to the platform provider.
- Third-party services we integrate with — report those to the respective vendor.
- Merchant storefronts themselves, and merchant-authored theme code.
- Findings that require a compromised device, browser, or merchant account.
- Volumetric denial of service, and any load or stress testing against production.
- Reports from an automated scanner with no demonstrated impact.
- Missing security headers or weak TLS configuration with no demonstrated exploit path.
- Social engineering of our staff, customers, or vendors; and physical attacks.
What we ask of researchers
- Use only test data and accounts you own. Do not access, modify, or exfiltrate other people's data.
- If you encounter personal data, stop, do not retain it, and tell us immediately in your report.
- Do not degrade service availability for merchants or shoppers.
- Give us a reasonable opportunity to remediate before any public disclosure. We ask for 90 days, and will work with you if you need a different timeline.
Recognition
We do not currently operate a paid bug bounty. We do maintain a thank-you list for researchers who report valid issues, with their permission.
Contact
Security reports: security@octaneai.com
Octane AI, Inc.
PO Box 7775 #94590
San Francisco, CA 94120-7775
