1. Security Approach
Leak Sight AI treats facility video, operational context, event evidence, and access records as potentially sensitive. Core controls include on-site processing where appropriate, encrypted transfer, configurable retention, role-based access, and audit logs.
Specific controls, responsibilities, recovery objectives, and notification terms for a pilot are documented in the applicable written agreement and deployment plan.
2. Reporting a Suspected Vulnerability
Use the Contact page and begin the message with “Security report.” Provide a high-level description, the affected public URL or component, the date observed, and a safe way to reproduce the issue without including sensitive data.
Leak Sight AI will use the supplied business contact details to arrange a more appropriate channel if logs, screenshots, or technical evidence are needed.
Do not include passwords, access tokens, exploit code, personal data, process video, or confidential facility details in the initial public form.
3. Research Boundaries
Research must be limited to public Leak Sight AI assets or an environment for which you have written authorization.
- Do not access, modify, download, retain, or disclose data belonging to another person, customer, or facility.
- Do not access cameras, sensors, edge devices, industrial networks, maintenance systems, or safety equipment without written authorization from all relevant owners.
- Do not use denial-of-service, destructive testing, social engineering, phishing, physical intrusion, automated high-volume scanning, or credential attacks.
- Stop research immediately if you encounter confidential information, personal data, or evidence of an active facility process.
- Do not publicly disclose a suspected vulnerability before Leak Sight AI has had a reasonable opportunity to investigate and address it.
4. What to Expect
Leak Sight AI will review reports made in good faith, prioritize them according to likely impact, and communicate when additional information is needed. Remediation timing depends on severity, reproducibility, affected components, and any customer coordination required.
Leak Sight AI does not promise payment, employment, public credit, or a particular response time through this policy.
5. Good-Faith Research
Leak Sight AI does not intend to pursue action solely for good-faith research that follows this policy, avoids harm, respects privacy, and stays within authorized scope. This statement does not authorize conduct prohibited by law or by third-party terms and cannot bind third parties.
6. Active Facility Incidents
The Contact page is not an emergency or live incident-response channel. If a security issue may affect an active industrial process, follow the facility’s approved cyber, safety, and emergency procedures first.