SyndaiSign inStart free

Vulnerability Disclosure Policy

Last updated: October 3, 2026

Eternex, Inc. dba Syndai ("Syndai," "we") builds Syndai, and keeping our customers' code and data safe is a top priority. We value the work of security researchers and welcome good-faith reports of vulnerabilities. This policy explains what is in scope, how to report a vulnerability, and the protections we extend to researchers who follow it.

Scope

This policy covers:

  • syndai.ai and its subdomains (marketing site and documentation).
  • The Syndai application and API (app.syndai.ai, api.syndai.ai).
  • The customer portal (portal.syndai.ai).

Systems and services operated by our third-party subprocessors (see our Subprocessor list at /legal/subprocessors) are not in scope. We cannot authorize testing against third parties; refer to their own disclosure policies.

How to report

Email security@syndai.ai with the details of your finding. If you need to send sensitive information, ask us for an encrypted channel and we will provide one. Machine-readable contact details are published at /.well-known/security.txt in accordance with RFC 9116.

To help us triage quickly, please include:

  • A clear description of the vulnerability and its potential impact.
  • Step-by-step instructions to reproduce it, including affected URLs, endpoints, or parameters.
  • Any reproduction code, sample requests, or screenshots.
  • The environment (browser, OS, tooling) where you observed it.
  • Your contact details and, if you would like credit, the name or handle to use.

Please submit one report per vulnerability, and give us reasonable time to investigate and remediate before disclosing to anyone else.

Safe harbor

We consider security research and vulnerability disclosure conducted in good faith and consistent with this policy to be authorized conduct. If you make a good-faith effort to comply with this policy during your research, we will:

  • Not pursue or support civil or criminal legal action against you, and not report you to law enforcement, for accidental or good-faith violations of this policy.
  • Consider your activities authorized under the Computer Fraud and Abuse Act, the DMCA, and applicable state computer-use laws such as California Penal Code section 502(c), and waive any DMCA claim against you for circumventing our technical protections for the sole purpose of your research under this policy.

If legal action is initiated by a third party against you for activity that complied with this policy, we will make it known that your actions were authorized. We cannot bind any third party, so this safe harbor does not extend to systems operated by others. If in doubt whether an action is authorized, ask us first at security@syndai.ai. We reserve the sole right to determine whether a violation was accidental or in good faith.

Out of scope

The following are not authorized under this policy. Do not:

  • Access, modify, or delete data belonging to other customers, or continue beyond the minimum access needed to demonstrate a vulnerability. If you encounter another customer's data, stop and report it immediately.
  • Perform denial-of-service (DoS/DDoS), volumetric, or resource-exhaustion testing, or otherwise degrade availability.
  • Conduct social engineering, phishing, or physical attacks against Syndai staff, contractors, users, or facilities.
  • Attempt to break out of, tamper with, or bypass build-sandbox isolation beyond a minimal reproduction, or use our sandboxes to attack other systems.
  • Ignore rate limits, run automated scanners that generate excessive traffic, or spam our forms and endpoints.
  • Publicly disclose a vulnerability before we have investigated and remediated it and agreed on timing with you.

Findings typically not eligible (unless you can show real security impact) include: missing best-practice HTTP headers, automated-tool reports without a working reproduction, self-XSS, clickjacking on pages with no sensitive action, and issues requiring a compromised device or highly unlikely user interaction.

Our commitment

When you report in line with this policy, we will:

  • Acknowledge your report within 5 business days.
  • Triage it, work to validate the issue, and keep you reasonably informed of our progress.
  • Investigate and remediate confirmed vulnerabilities as quickly as their severity warrants, and let you know when the issue is resolved.
  • Credit you for the discovery once the issue is fixed, if you would like to be named.

We do not currently run a paid bug-bounty program, and no monetary reward is promised unless we separately offer one in writing. We coordinate any public disclosure with you.

Contact

Security contact: security@syndai.ai.

Eternex, Inc. dba Syndai, 2261 Market Street STE 24499, San Francisco, CA 94114.