Responsible Disclosure Policy

Last updated: 11 July 2026

SEELE Technology Limited ("Seele") takes the security of seeles.ai, SeeleAgent, and our infrastructure seriously. We value the work of security researchers and welcome reports of potential vulnerabilities. This policy explains how to report an issue and what you can expect from us.

1. Scope

This policy covers vulnerabilities in Seele-owned and operated systems, including seeles.ai, the SeeleAgent application, and our public APIs. It does not cover third-party services we do not control, or issues that are purely informational and carry no realistic security impact. If you are unsure whether something is in scope, report it and we will let you know.

2. How to report

Please email a detailed report to security@seeles.ai. To help us reproduce and resolve the issue quickly, include:

  • A clear description of the vulnerability and its potential impact.
  • Step-by-step instructions to reproduce it, including affected URLs, endpoints, or components.
  • Any proof-of-concept code, screenshots, or logs (please minimize any sensitive data).

Please give us a reasonable opportunity to investigate and remediate before disclosing the issue publicly or to any third party.

3. Rules of engagement — what not to do

When researching, you must not:

  • Access, modify, delete, or destroy data that does not belong to you.
  • Compromise the privacy of our users or view, retain, or exfiltrate personal data.
  • Perform denial-of-service (DoS/DDoS) attacks, resource-exhaustion tests, or any action that degrades or disrupts our services.
  • Use social engineering, phishing, or physical attacks against our staff, users, or facilities.
  • Run automated scanning that generates excessive traffic or otherwise harms availability.

Please act in good faith, limit your testing to your own accounts and test data, and stop as soon as you confirm a vulnerability.

4. Safe harbor

If you make a good-faith effort to comply with this policy, we will consider your research authorized, we will not pursue or support legal action against you in connection with your report, and we will work with you to understand and resolve the issue promptly. This safe harbor does not apply to activity that is malicious, that violates the law, or that harms our users or systems.

5. What to expect from us

  • Acknowledgment: We aim to confirm receipt of your report within 72 hours.
  • Updates: We will provide periodic updates as we investigate and work toward a fix.
  • Resolution: We will prioritize remediation based on severity and impact, and we will let you know when the issue is resolved.

We do not currently operate a paid bug bounty program, but we are grateful for responsible reports and are happy to acknowledge researchers who help keep our users safe.

6. Contact

For all security matters, please contact security@seeles.ai.