ethira
Features
AboutBlogSign inBook a demo
Security

Responsible Disclosure

Last updated: August 21, 2026 · Ethira AB

Report security vulnerabilities in Ethira privately to security@ethira.dev. We acknowledge reports within 3 business days, and we will work with you on a fix before anything is made public.

How to report

Email security@ethira.dev. Do not open a public GitHub issue, post on social media, or discuss the issue with anyone outside Ethira until we have resolved it or agreed a disclosure date with you.

Include:

  • A clear description of the issue and its impact
  • The affected URL, product, or component
  • Steps to reproduce, or a proof of concept
  • Any relevant logs, screenshots, or request/response samples
  • Your contact details and, if you want, a name for acknowledgement

Encrypt the report if it contains customer data or credentials. We do not currently publish a PGP key; describe live secrets rather than attaching them.


Our commitments

  • We acknowledge reports within 3 business days.
  • We give you an initial assessment of severity and next steps as soon as we have one.
  • We keep you informed while we investigate and ship a fix.

This is a coordinated disclosure programme, not a paid bug bounty. Significant in-scope findings are credited on our Hall of Fame, with a stable link you can cite. Tell us the name you want listed.


Scope

In scope

  • The Ethira platform at app.ethira.dev
  • The Ethira API at api.ethira.dev
  • The marketing site at ethira.dev
  • The official Ethira browser extension
  • The official Ethira MCP server

Out of scope

  • Third-party products we integrate with or list as subprocessors — report those to the vendor
  • Denial of service, volumetric flooding, or spam
  • Social engineering or phishing of Ethira staff or customers
  • Physical attacks against offices or staff
  • Findings that require physical access, stolen credentials, or malware on an end-user device
  • Automated scanner output with no demonstrated security impact

Rules of engagement

Test only against accounts and workspaces you own or that we have explicitly authorised.

If you find a way to access another customer's data, stop. Do not exfiltrate, modify, or persist that data. Note enough to demonstrate the issue and email us.

Do not:

  • Degrade service for other users
  • Run aggressive automated scans against production
  • Attempt to extort, ransom, or set a public deadline as a condition of disclosure

Legal safe harbour

If you follow this policy in good faith, Ethira will not pursue legal action against you or ask law enforcement to do so for the research described in your report. This is not a licence to attack systems outside the scope above, to access other customers' data beyond what is needed to demonstrate an issue, or to violate applicable law.

If you are unsure whether a test is allowed, email security@ethira.dev first.


Coordinated disclosure

Please hold off on public disclosure until we have had time to investigate and ship a fix. We will agree timing with you. If we cannot meet a date you have in mind, we will say so and explain why.

Hall of Fame

Researchers whose reports led to a security fix, listed here with their consent. Each name has a permanent link you can cite. We publish the name, affiliation, and date — never what was found.

Adrian De Gendt

CYBRET AI

August 2026

Reserved

The next name goes here

Named with your consent, after a fix ships.

Contact

  • Security reports: security@ethira.dev
  • Privacy: privacy@ethira.dev
  • Everything else: hello@ethira.dev
ethira

Govern every asset. Automatically.

Platform

  • Features
  • Slack app
  • Guides
  • AI Governance

Use Cases

  • Shadow AI Discovery
  • AI Agent Governance
  • Third-Party Risk (TPRM)
  • ICT Risk Management
  • DORA RoI Reporting

Company

  • About
  • Blog
  • FAQ
  • Brand
  • Privacy Policy
  • Terms of Service
  • Subprocessors
  • Security
  • Contact

© 2026 Ethira AB · Luntmakargatan 26, 111 37 Stockholm, Sweden

Privacy PolicyTerms of ServiceSubprocessorsSecurity