# Yardlight Vulnerability Disclosure Policy # https://yardlight.app/.well-known/security.txt # Spec: RFC 9116 (https://datatracker.ietf.org/doc/html/rfc9116) # # Yardlight is a first-party AI help widget by MASONBYTE LLC. It embeds # inside other applications, so a vulnerability here is somebody else's # product and somebody else's users. We welcome reports from researchers # acting in good faith. # # Scope: yardlight.app and all subdomains; this repository's widget, # answer service, and any released package. # # Out of scope: third-party services we build on (report directly to them): # Netlify — security@netlify.com # Anthropic — security@anthropic.com # GitHub — https://hackerone.com/github Contact: mailto:support@masonbyte.com Expires: 2027-08-01T00:00:00.000Z Preferred-Languages: en Canonical: https://yardlight.app/.well-known/security.txt Policy: https://github.com/MasonByteLLC/yardlight/blob/main/SECURITY.md # The properties Yardlight is built to hold — a report that breaks one of # these is a valid finding, and the most useful thing you can send us: # 1. The widget holds the user's token, never a master key. A compromised # widget should be exactly as dangerous as a compromised user session. # 2. The browser never talks to the model provider directly; the API key # lives only in the answer service's environment. # 3. The assistant has no write access to anything. # 4. Answers come only from the knowledgebase, user-scoped read-only # lookups, and the conversation — prompt injection via indexed content # is in scope. # 5. Logs keep questions, never retrieved data, and never secrets. # 6. It ships inert — no configuration means no answers. # # What to include in a report: # - Description of the vulnerability + impact # - Steps to reproduce (proof of concept welcome but not required) # - Your name / handle for acknowledgment (optional) # # What we ask: # - Give us reasonable time to fix before public disclosure # (default: 90 days, negotiable for severe issues) # - Don't access data beyond what's needed to demonstrate the issue # - Don't test against a host application that isn't yours # - Don't perform DoS / DDoS testing or automated scanning that # impacts availability # # MasonByte LLC — SDVOSB — CAGE 7BAJ0 — UEI ZERAMJ6UEML9 # Accokeek, MD