Advertised via security.txt on every Preferium-managed Worker per RFC 9116 (R168).

Vulnerability Disclosure Policy

Last updated: 2026-05-19 Effective version: 1.0 (draft — pending legal review)

Preferium AS welcomes responsible reports of security vulnerabilities affecting Preferium AI Edge. This policy describes scope, safe harbor, the reporting channel, and our response commitments.

This policy is also advertised in machine-readable form at /.well-known/security.txt per RFC 9116.


1. Scope

In scope:

Out of scope:

2. Safe harbor

We will not pursue legal action against you for good-faith security research that:

If you are unsure whether your testing is within scope, contact us first at security@preferium.com.

3. How to report

Preferred channel: Email security@preferium.com with:

Sensitive reports: for any report containing exploit payloads, customer data, or session tokens, email security@preferium.com first and we will arrange an encrypted channel before you send details.

Languages accepted: English, Norwegian.

We do not currently offer monetary bounties. A formal bug bounty program is planned for R175+.

4. Response SLA

StageTarget
Acknowledge receipt72 hours
Initial triage + severity7 days
Status update or fix shipped30 days
Coordinated disclosure90 days after acknowledgement, or upon fix shipping, whichever is earlier

If we miss an SLA, we will tell you in advance and explain why.

5. Public credit

Researchers who report valid vulnerabilities and who request it will be publicly credited (with their consent) when the fix ships — name, date, and a one-line description of the vulnerability class (no exploit details).

6. Coordinated disclosure

We follow ISO/IEC 29147:2018 coordinated disclosure:

  1. You report privately to security@preferium.com
  2. We confirm + triage
  3. We fix
  4. We notify affected customers if customer data was at risk
  5. We agree a public disclosure timeline with you (default 90 days)
  6. Public advisory published (linked from this trust center) once disclosure is agreed

Contact

security@preferium.com — for sensitive payloads, email first and we will arrange an encrypted channel.

For non-security questions, see TERMS.md and PRIVACY.md.