Vulnerability Disclosure Policy

Security & Disclosure

Standard: RFC 9116 / security.txt | Last Updated: July 20, 2026

1. Commitment to AI Safety

As an independent AI safety and security laboratory, Sleepers Research welcomes responsible disclosure of vulnerabilities discovered within our security middleware prototypes, MCP proxies, or public infrastructure endpoints.

2. How to Report a Vulnerability

If you identify a security issue, prompt injection exploit, or authorization bypass in any project published by Sleepers Research, please submit your findings to:

Our standard security.txt manifest is available at /.well-known/security.txt.

3. Responsible Research Guidelines

  • Do not perform destructive testing that interrupts live services or alters production data.
  • Provide reasonable time for our team to review and patch reported vulnerabilities before public disclosure.
  • Avoid privacy violations or data exfiltration during vulnerability validation.

4. Safe Harbor

Security research conducted in good faith and in compliance with these guidelines will be treated as authorized conduct. We will not pursue legal action against researchers acting responsibly.