Security

Report a vulnerability.

Good-faith research is welcome on this site and on the Circle360 assessment product. We would rather hear from you than read it in a write-up.

How to report

Email security@circle360.ai.

Include enough to reproduce: URL or component, steps, impact, and any proof-of-concept. Do not include customer tenant data or credentials.

Machine-readable contact: /.well-known/security.txt.

Scope

In scope: circle360.ai, the Circle360 AI assessment tooling (collectors, analyzers, report generator, installer), and the handling of tenant data those tools produce.

Out of scope: third-party services we do not operate (Formspree, Google Fonts, Microsoft Graph), social-engineering of staff, and denial-of-service.

Coordinated disclosure

Give us 90 days to fix and deploy before public disclosure, unless we agree a shorter window. We will acknowledge receipt within 5 business days and keep you informed.

We will not pursue legal action against researchers who act in good faith, stay within this policy, and do not access, exfiltrate, or destroy data beyond what is needed to demonstrate the issue.