> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tightknit.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Vulnerability Disclosure Policy

> How to report security vulnerabilities to Tightknit

This policy governs how security researchers should raise security concerns with us and how we respond.

Data security is a top priority for Tightknit, and we believe that working with skilled security researchers can identify weaknesses in any technology.

If you believe you’ve found a security vulnerability in our service, please notify us and we will work with you to resolve the issue promptly.

### Disclosing a weakness

* If you believe you’ve discovered a potential vulnerability, please email us at [security@tightknit.ai](mailto:security@tightknit.ai). We will acknowledge your email within ten business days.
* Provide us with a reasonable amount of time to resolve the issue before disclosing it to the public or a third party. We aim to resolve critical issues within one week of disclosure.
* Make a good faith effort to avoid violating privacy, destroying data, or interrupting or degrading the Tightknit service. Please only interact with accounts you own or for which you have explicit permission.

### In scope

* [https://tightknit.ai](https://tightknit.ai)
* [https://api.tightknit.ai](https://api.tightknit.ai)
* any Tightknit community website
* the Tightknit Slack app

### Exclusions

While researching, please refrain from:

* Distributed Denial of Service (DDoS)
* Spamming
* Automated penetration tests or vulnerability scans
* Social engineering or phishing of Tightknit employees or contractors
* Any attacks against Tightknit's physical property or data centers
* Password brute force
* Clickjacking on pages with no sensitive actions
* Missing security headers (unless you can prove exploitability)
* Security issues only reproducible under highly unlikely conditions (using outdated or exotic web browsers, operating systems, or insecure internet connections)


## Related topics

- [Tightknit Infrastructure & Application Security](/security/application.md)
- [Tightknit Data Security & Privacy](/security/data.md)
- [Navigation & Routes](/community-site/navigation.md)
- [SOC 2 Compliance](/security/soc-2.md)
- [GDPR Compliance](/security/gdpr.md)
