Contact: mailto:Help@humantic.ai Canonical: https://humantic.ai/.well-known/security.txt Expires: 2026-12-31T23:59:59Z Preferred-Languages: en # VULNERABILITY POLICY # # At Humantic AI, we consider the security of our systems and buyer # intelligence data a top priority. # # Humantic AI holds SOC 2 Type II certification and adheres to GDPR and CCPA # requirements across all data processing operations. # # No matter how much effort we put into system security, there can still be # vulnerabilities present. # # If you discover a vulnerability, we would like to know about it so we can # take steps to address it as quickly as possible. # # We ask you to help us better protect our clients and our systems. # # MCP AND AI INTEGRATION SECURITY # # Humantic AI operates an MCP (Model Context Protocol) server that allows AI # assistants and agentic workflows to access buyer intelligence data on behalf # of authenticated users. # # All MCP-based access requires explicit user authentication and operates # within the same permission scope as direct platform access. # # Data returned through MCP sessions is isolated per workspace and subject to # the same no-storage architecture that governs all other platform # interactions. # # Security vulnerabilities specific to the MCP integration, including # authentication bypass, session escalation, or workspace data isolation # failures, should be reported with priority using the contact above. # # OUT OF SCOPE VULNERABILITIES # # Clickjacking on pages with no sensitive actions does not require reporting. # The same applies to unauthenticated logout or login CSRF, and attacks # requiring physical access to a user device or social engineering. # # We also do not require reports for activity that disrupts service such as # DoS attacks, content spoofing, text injection without a demonstrated attack # vector, email spoofing, missing DNSSEC or CAA headers, user enumeration, and # dead links. # # TESTING GUIDELINES # # Do not run automated scanners on other customer projects as this can run up # costs for our users. # # Aggressively configured scanners might inadvertently disrupt services or # violate terms from our upstream providers. # # Our security systems cannot distinguish hostile reconnaissance from whitehat # research. # # If you wish to run an automated scanner, notify us at our security contact # and only run it on your own project. # # Do not take advantage of the vulnerability you have discovered by # downloading excess data or modifying other people's data. # # REPORTING GUIDELINES # # Provide sufficient information to reproduce the problem so we will be able # to resolve it as quickly as possible. # # DISCLOSURE GUIDELINES # # In order to protect our customers, do not reveal the problem to others until # we have researched and informed our affected customers. # # If you want to publicly share your research about Humantic AI, you should # share a draft with us for review at least 30 days prior to the publication # date. # # Data regarding any Humantic AI customer projects or employees must never be # included in public disclosures. # # WHAT WE PROMISE # # We will respond to your report within 5 business days with our evaluation # and an expected resolution date. # # We will keep you informed of the progress towards resolving the problem. # # In the public information concerning the problem reported, we will give your # name as the discoverer of the problem unless you desire otherwise. # # If you have followed the instructions above, we will not take any legal # action against you in regard to the report. # # We will handle your report with strict confidentiality, and not pass on your # personal details to third parties without your permission. # # LAST UPDATED: August 2026