Vulnerability Disclosure Policy
Security & Disclosure
Standard: RFC 9116 / security.txt | Last Updated: July 20, 2026
1. Commitment to AI Safety
As an independent AI safety and security laboratory, Sleepers Research welcomes responsible disclosure of vulnerabilities discovered within our security middleware prototypes, MCP proxies, or public infrastructure endpoints.
2. How to Report a Vulnerability
If you identify a security issue, prompt injection exploit, or authorization bypass in any project published by Sleepers Research, please submit your findings to:
Email: research@sleepersai.com
Our standard security.txt manifest is available at /.well-known/security.txt.
3. Responsible Research Guidelines
- Do not perform destructive testing that interrupts live services or alters production data.
- Provide reasonable time for our team to review and patch reported vulnerabilities before public disclosure.
- Avoid privacy violations or data exfiltration during vulnerability validation.
4. Safe Harbor
Security research conducted in good faith and in compliance with these guidelines will be treated as authorized conduct. We will not pursue legal action against researchers acting responsibly.