Security & trust

Vulnerability Disclosure Policy

Last updated July 2026

Security is core to what we do — we deploy AI that acts on real systems, so we hold ourselves to a high bar and we welcome the security research community's help. If you believe you've found a vulnerability, this policy explains how to report it, what to expect, and the protections we offer good-faith researchers.

01How to report

Email security@tokoaido.com. Please include enough detail to reproduce and assess the issue: the affected component or URL, a description of the vulnerability and its impact, and clear steps to reproduce (a proof-of-concept, screenshots or a short video help). Let us know if you'd like to be credited.

02What to expect from us

  • Acknowledgement of your report, typically within three business days
  • Triage and a severity assessment, with an initial response on next steps
  • Progress updates as we investigate and remediate
  • Coordinated disclosure — we'll agree timing with you before any public detail

03Safe harbor

We will not pursue or support legal action against researchers who make a good-faith effort to comply with this policy. We consider security research and vulnerability disclosure conducted under this policy to be authorized, and we'll work with you to understand and resolve the issue quickly.

04In scope

  • The Tokoaido application and its APIs
  • The public marketing site and the seeded demo environment
  • Issues such as authentication or authorization flaws, tenant-isolation gaps, sensitive-data exposure, injection, and broken access controls

05Out of scope

  • Denial-of-service or volumetric testing
  • Social engineering, phishing, or physical attacks against our people or facilities
  • Findings from automated scanners without a demonstrated, exploitable impact
  • Best-practice suggestions with no security impact (e.g., missing headers on non-sensitive pages)
  • Vulnerabilities in third-party services we don't control
  • Content or data in the seeded demo, which is synthetic

06Rules of engagement

  • Use only your own test accounts; never access, modify or delete data that isn't yours
  • Do not run denial-of-service tests or degrade the service for others
  • Do not exfiltrate data — a minimal proof-of-concept is enough
  • If you encounter sensitive data, stop, do not save it, and tell us immediately
  • Give us reasonable time to remediate before any public disclosure

07Recognition

With your permission, we're glad to credit researchers who help us keep customers safe. Thank you for reporting responsibly — security@tokoaido.com.