Vulnerability Disclosure Policy
Last updated July 2026
Security is core to what we do — we deploy AI that acts on real systems, so we hold ourselves to a high bar and we welcome the security research community's help. If you believe you've found a vulnerability, this policy explains how to report it, what to expect, and the protections we offer good-faith researchers.
01How to report
Email security@tokoaido.com. Please include enough detail to reproduce and assess the issue: the affected component or URL, a description of the vulnerability and its impact, and clear steps to reproduce (a proof-of-concept, screenshots or a short video help). Let us know if you'd like to be credited.
02What to expect from us
- Acknowledgement of your report, typically within three business days
- Triage and a severity assessment, with an initial response on next steps
- Progress updates as we investigate and remediate
- Coordinated disclosure — we'll agree timing with you before any public detail
03Safe harbor
We will not pursue or support legal action against researchers who make a good-faith effort to comply with this policy. We consider security research and vulnerability disclosure conducted under this policy to be authorized, and we'll work with you to understand and resolve the issue quickly.
04In scope
- The Tokoaido application and its APIs
- The public marketing site and the seeded demo environment
- Issues such as authentication or authorization flaws, tenant-isolation gaps, sensitive-data exposure, injection, and broken access controls
05Out of scope
- Denial-of-service or volumetric testing
- Social engineering, phishing, or physical attacks against our people or facilities
- Findings from automated scanners without a demonstrated, exploitable impact
- Best-practice suggestions with no security impact (e.g., missing headers on non-sensitive pages)
- Vulnerabilities in third-party services we don't control
- Content or data in the seeded demo, which is synthetic
06Rules of engagement
- Use only your own test accounts; never access, modify or delete data that isn't yours
- Do not run denial-of-service tests or degrade the service for others
- Do not exfiltrate data — a minimal proof-of-concept is enough
- If you encounter sensitive data, stop, do not save it, and tell us immediately
- Give us reasonable time to remediate before any public disclosure
07Recognition
With your permission, we're glad to credit researchers who help us keep customers safe. Thank you for reporting responsibly — security@tokoaido.com.