Vulnerability Disclosure Policy

FieldValue
Document ownerChief Technology Officer (role)
Version1.0
Effective date2026-06-16
Last reviewed2026-06-16
ClassificationPublic
Contactsecurity@percuity.ai

1. Introduction and Purpose

Percuity, the AI advertising platform operated by Fibonacci, Inc. (“Percuity,” “we,” “us”), is committed to protecting the security of our systems and the data entrusted to us by our customers. We recognize that security researchers play an important role in helping us identify and remediate weaknesses.

This Vulnerability Disclosure Policy (VDP) describes how to report security vulnerabilities to us, what you can expect from us in return, and the conditions under which we authorize good-faith security research. We welcome reports from researchers and will work with you to understand, validate, and resolve issues responsibly.

This policy is published as a public document and reflects industry best practice, including the spirit of ISO/IEC 29147 (vulnerability disclosure) and U.S. CISA guidance on vulnerability disclosure programs.


2. Scope

2.1 In Scope

The following assets are in scope for this policy:

2.2 Out of Scope

The following activities and targets are out of scope and are not authorized under this policy:

If you are unsure whether a target or technique is in scope, contact us at security@percuity.ai before proceeding.


3. Safe Harbor and Authorization

If you make a good-faith effort to comply with this policy during your security research, we will consider that research to be authorized. We will not initiate or pursue legal action against you for activity conducted in accordance with this policy, and we will take steps to make known that your actions were authorized if a third party raises a concern.

This authorization is subject to the following conditions:

  1. You comply with all terms of this policy, including the scope and researcher guidelines.
  2. You act in good faith and avoid privacy violations, data destruction, and service disruption.
  3. You access, modify, or store only the minimum data necessary to demonstrate a vulnerability.
  4. You give us a reasonable opportunity to investigate and remediate before any public disclosure.

This policy does not authorize activity that violates applicable law. If legal action is initiated by a third party against you for activity conducted under this policy, and you have complied with this policy, we will take reasonable steps to make it known that your actions were authorized. This policy does not waive any rights of third parties.


4. How to Report

Send vulnerability reports by email to security@percuity.ai.

To help us triage and reproduce the issue quickly, please include the following:

Please submit reports in English where possible. You may report anonymously, though contact details help us follow up with questions and provide status updates.

Our contact information is also published in machine-readable form at percuity.ai/.well-known/security.txt in accordance with RFC 9116.


5. Researcher Guidelines

5.1 Please Do

5.2 Please Do Not


6. Our Commitment and Communication Timeline

We aim to keep you informed throughout the process. The timelines below are targets we strive to meet and are stated as goals rather than guarantees.

StageTarget
Acknowledge receipt of your reportWithin 3 business days
Initial assessment and triageWithin 10 business days
Ongoing status updatesAt meaningful milestones and on reasonable request
Coordinated disclosureAfter remediation, in coordination with you

7. Remediation Targets by Severity

Once a vulnerability is validated, we prioritize remediation based on severity. The timelines below are internal targets, measured from validation, and represent goals rather than binding commitments. Actual timing depends on complexity, dependencies, and risk.

SeverityRemediation target
CriticalWithin 30 days
HighWithin 60 days
MediumWithin 90 days
LowBest-effort, as resources allow

8. Recognition

We are grateful to the security researchers who help us protect our systems and our customers.

We do not currently operate a paid bug-bounty program, and we do not offer monetary rewards for reports at this time. With your permission, we are happy to acknowledge your contribution after a reported issue has been resolved.


By submitting a report, you agree that we may use the information you provide to investigate and remediate the issue. Do not include more personal data than is necessary to describe the vulnerability. We handle any personal data contained in a report in accordance with applicable law and our privacy practices.

This policy may be updated from time to time. The version and review dates in the metadata table above reflect the current revision. Nothing in this policy is intended to create a contractual obligation or to limit rights or remedies available under applicable law.