Back to Home

Security

Vulnerability Disclosure Policy

Last Updated: September 10, 2026

Octane AI, Inc. ("Octane AI") builds quiz and personalization software used by online merchants. We process shopper and merchant data on their behalf, and we treat reports of security weaknesses as high-priority work. We welcome reports from security researchers, customers, and merchants, and we will not pursue legal action against researchers who follow this policy in good faith.

How to report a vulnerability

Please email security@octaneai.com. Include:

  • A description of the vulnerability and its potential impact.
  • Steps to reproduce, with request/response detail or a proof of concept.
  • Affected URLs, endpoints, or components.
  • Any relevant configuration (browser, OS, tooling).
  • How you would like to be credited, if at all.

If you need to share sensitive material, ask us for our PGP key in your first message.

Our response commitments

  • Acknowledgement of your report within 2 business days.
  • Initial triage and severity assignment within 5 business days.
  • Status updates at least every 10 business days while a report is open.
  • Notification when the issue is resolved.

Remediation timelines by severity

We assign severity using CVSS v3.1, adjusted for exploitability in our environment and the sensitivity of the data at risk.

SeverityCVSS v3.1Target remediation
Critical9.0–10.0Mitigation within 24 hours; permanent fix within 7 days
High7.0–8.930 days
Medium4.0–6.990 days
Low0.1–3.9180 days, or documented as accepted risk

For confirmed Critical findings we prioritize immediate mitigation (a feature flag, a WAF rule, or credential rotation) ahead of the permanent fix, so that any exposure ends as quickly as possible.

Scope

In scope:

  • octaneai.com and app.octaneai.com, including the merchant dashboard.
  • The Octane AI app, including its app proxy and storefront quiz embed.
  • Our public APIs and webhook endpoints.
  • Our authentication and session-handling flows.

Out of scope:

  • The e-commerce platform's own infrastructure — report those to the platform provider.
  • Third-party services we integrate with — report those to the respective vendor.
  • Merchant storefronts themselves, and merchant-authored theme code.
  • Findings that require a compromised device, browser, or merchant account.
  • Volumetric denial of service, and any load or stress testing against production.
  • Reports from an automated scanner with no demonstrated impact.
  • Missing security headers or weak TLS configuration with no demonstrated exploit path.
  • Social engineering of our staff, customers, or vendors; and physical attacks.

What we ask of researchers

  • Use only test data and accounts you own. Do not access, modify, or exfiltrate other people's data.
  • If you encounter personal data, stop, do not retain it, and tell us immediately in your report.
  • Do not degrade service availability for merchants or shoppers.
  • Give us a reasonable opportunity to remediate before any public disclosure. We ask for 90 days, and will work with you if you need a different timeline.

Recognition

We do not currently operate a paid bug bounty. We do maintain a thank-you list for researchers who report valid issues, with their permission.

Contact

Security reports: security@octaneai.com

Octane AI, Inc.

PO Box 7775 #94590

San Francisco, CA 94120-7775