Vulnerability Disclosure Policy
| Field | Value |
|---|---|
| Document owner | Chief Technology Officer (role) |
| Version | 1.0 |
| Effective date | 2026-06-16 |
| Last reviewed | 2026-06-16 |
| Classification | Public |
| Contact | security@percuity.ai |
1. Introduction and Purpose
Percuity, the AI advertising platform operated by Fibonacci, Inc. (“Percuity,” “we,” “us”), is committed to protecting the security of our systems and the data entrusted to us by our customers. We recognize that security researchers play an important role in helping us identify and remediate weaknesses.
This Vulnerability Disclosure Policy (VDP) describes how to report security vulnerabilities to us, what you can expect from us in return, and the conditions under which we authorize good-faith security research. We welcome reports from researchers and will work with you to understand, validate, and resolve issues responsibly.
This policy is published as a public document and reflects industry best practice, including the spirit of ISO/IEC 29147 (vulnerability disclosure) and U.S. CISA guidance on vulnerability disclosure programs.
2. Scope
2.1 In Scope
The following assets are in scope for this policy:
- The Percuity production web application and its API
- The percuity.ai website
2.2 Out of Scope
The following activities and targets are out of scope and are not authorized under this policy:
- Social engineering of Percuity employees, contractors, customers, or vendors (including phishing and pretexting)
- Physical attacks against offices, facilities, or hardware
- Denial-of-service (DoS) and distributed denial-of-service (DDoS) attacks
- Automated scanning that degrades, disrupts, or materially impairs service availability or performance
- Third-party services and platforms that we do not own or control
If you are unsure whether a target or technique is in scope, contact us at security@percuity.ai before proceeding.
3. Safe Harbor and Authorization
If you make a good-faith effort to comply with this policy during your security research, we will consider that research to be authorized. We will not initiate or pursue legal action against you for activity conducted in accordance with this policy, and we will take steps to make known that your actions were authorized if a third party raises a concern.
This authorization is subject to the following conditions:
- You comply with all terms of this policy, including the scope and researcher guidelines.
- You act in good faith and avoid privacy violations, data destruction, and service disruption.
- You access, modify, or store only the minimum data necessary to demonstrate a vulnerability.
- You give us a reasonable opportunity to investigate and remediate before any public disclosure.
This policy does not authorize activity that violates applicable law. If legal action is initiated by a third party against you for activity conducted under this policy, and you have complied with this policy, we will take reasonable steps to make it known that your actions were authorized. This policy does not waive any rights of third parties.
4. How to Report
Send vulnerability reports by email to security@percuity.ai.
To help us triage and reproduce the issue quickly, please include the following:
- A clear description of the vulnerability and the affected component
- Step-by-step instructions to reproduce the issue
- An assessment of the potential impact
- The affected URL, endpoint, or parameter
- Any proof-of-concept (PoC) code, scripts, screenshots, or request/response captures
Please submit reports in English where possible. You may report anonymously, though contact details help us follow up with questions and provide status updates.
Our contact information is also published in machine-readable form at percuity.ai/.well-known/security.txt in accordance with RFC 9116.
5. Researcher Guidelines
5.1 Please Do
- Report a vulnerability promptly after you discover it.
- Avoid privacy violations and minimize interaction with accounts and data that are not your own.
- Limit testing to in-scope assets.
- Give us reasonable time to investigate and remediate before disclosing publicly.
- Stop testing and notify us immediately if you encounter sensitive data (such as personal data, credentials, or proprietary information).
5.2 Please Do Not
- Access, modify, or exfiltrate data beyond the minimum needed to demonstrate the vulnerability.
- Perform denial-of-service or any test that degrades service availability.
- Send spam or unsolicited bulk messages.
- Social-engineer, phish, or otherwise target Percuity staff, customers, or vendors.
- Publicly disclose the vulnerability before we have had a reasonable opportunity to coordinate disclosure with you.
6. Our Commitment and Communication Timeline
We aim to keep you informed throughout the process. The timelines below are targets we strive to meet and are stated as goals rather than guarantees.
| Stage | Target |
|---|---|
| Acknowledge receipt of your report | Within 3 business days |
| Initial assessment and triage | Within 10 business days |
| Ongoing status updates | At meaningful milestones and on reasonable request |
| Coordinated disclosure | After remediation, in coordination with you |
7. Remediation Targets by Severity
Once a vulnerability is validated, we prioritize remediation based on severity. The timelines below are internal targets, measured from validation, and represent goals rather than binding commitments. Actual timing depends on complexity, dependencies, and risk.
| Severity | Remediation target |
|---|---|
| Critical | Within 30 days |
| High | Within 60 days |
| Medium | Within 90 days |
| Low | Best-effort, as resources allow |
8. Recognition
We are grateful to the security researchers who help us protect our systems and our customers.
We do not currently operate a paid bug-bounty program, and we do not offer monetary rewards for reports at this time. With your permission, we are happy to acknowledge your contribution after a reported issue has been resolved.
9. Legal and Privacy Note
By submitting a report, you agree that we may use the information you provide to investigate and remediate the issue. Do not include more personal data than is necessary to describe the vulnerability. We handle any personal data contained in a report in accordance with applicable law and our privacy practices.
This policy may be updated from time to time. The version and review dates in the metadata table above reflect the current revision. Nothing in this policy is intended to create a contractual obligation or to limit rights or remedies available under applicable law.