Report clearly
Include affected page, reproduction steps, browser/runtime context, and expected impact.
Security reports
A public route for reporting vulnerabilities, unsafe behavior, data exposure, or governance bypass concerns.
Include affected page, reproduction steps, browser/runtime context, and expected impact.
Do not access, modify, destroy, or exfiltrate data that is not yours.
Website, public interfaces, deployment instructions, and AI governance claims are in scope.
Sensitive details should be shared directly with TAHAI Web Services.
Reports should be reviewed, reproduced where possible, and tracked to resolution.
Coordinated disclosure can include public thanks where appropriate.