Vulnerability Disclosure Policy (VDP)
Effective date: 2026-07-07 (draft) · Version: 0.9
TXR Enterprises LLC ("CINTA", "we", "us") values the work of independent security researchers. This policy describes how to report a security vulnerability in the CINTA platform, what you can expect from us, and the safe-harbor protections we extend to good-faith research.
Draft v0.9 — pending review by licensed counsel before production use. Have counsel confirm the safe-harbor language against applicable computer- crime and DMCA-equivalent statutes before this policy governs a live researcher report.
1. Scope
In scope: the CINTA platform and its first-party domains/subdomains, the CINTA API, and the CINTA mobile/desktop clients, to the extent owned and operated by TXR Enterprises LLC. Out of scope: third-party services CINTA integrates with but does not operate (OAuth providers, model providers, payment processors, and any customer-directed connected accounts) — report those to the respective vendor. Social-engineering targeting our staff, customers, or contractors is out of scope for this program.
2. How to report
We prefer, in order:
In-Trix
/report— from inside the CINTA product, run the/reportcommand. This opens a private channel directly to the security team and is the fastest path to a human.Email
security@cinta-ai.com— if you cannot reach the product, or the issue affects infrastructure outside a live session.security.txt— machine-readable contact per RFC 9116, published at/.well-known/security.txt, pointing to this policy.
Include: a clear description of the vulnerability, the impact you believe it has, steps to reproduce (proof-of-concept code/screenshots welcome), and the affected URL(s)/endpoint(s). Reports in English or Spanish are both accepted.
3. Safe harbor
We consider security research conducted consistent with this policy to be:
Authorized in accordance with the applicable computer-crime and anti-hacking laws (e.g. the U.S. Computer Fraud and Abuse Act and equivalent statutes elsewhere), and we will not initiate or support legal action against you for that research.
Exempt from DMCA (or local equivalent) claims for circumventing technological measures used to protect the scope described above, to the extent necessary to conduct the research described here.
Treated as authorized under any applicable CINTA terms that would otherwise restrict testing, solely for the duration and purpose of good-faith research under this policy.
This safe harbor applies only to research that:
Is performed in good faith, aimed at finding and reporting a vulnerability, not at exploiting it beyond what is necessary to demonstrate impact.
Avoids privacy violations — do not access, retain, or exfiltrate data belonging to other users beyond the minimum needed to prove the issue, and disclose immediately if you inadvertently access such data.
Avoids data destruction or modification of production systems or data.
Avoids service degradation — no denial-of-service testing, no high-volume automated scanning that could impact availability for other users.
Avoids social engineering and physical attacks against our staff, customers, contractors, offices, or data centers.
Gives us a reasonable opportunity to investigate and remediate before any public disclosure (see §5).
If in doubt about whether a specific test is authorized, ask us first at security@cinta-ai.com before proceeding — we would rather answer a question than receive an incident.
4. Our commitment (SLA)
| Milestone | Target |
|---|---|
| Acknowledgment of report | within 3 business days |
| Initial triage / severity assessment | within 7 days |
| Coordinated disclosure window | 90 days from acknowledgment, extensible by mutual agreement if remediation needs more time |
We will keep you informed of progress and let you know when a fix ships.
5. Coordinated disclosure
Please give us the disclosure window in §4 before publishing details publicly. We are happy to coordinate a joint disclosure timeline, credit you in the acknowledgments below (unless you prefer to stay anonymous), and will tell you as soon as the fix is deployed so you are not waiting in the dark.
6. Rewards
We do not run a contractual bug-bounty program at this time. We may, at our sole discretion, offer recognition or a discretionary reward for reports that have real security impact — this is never guaranteed, never a term of this policy, and any payment is a hard gate requiring owner approval, not an automatic entitlement of submitting a report.
7. Acknowledgments
We are grateful to the researchers who help keep CINTA secure. Researchers who report a valid, in-scope vulnerability under this policy may be listed here (with consent).
<!-- Hall of fame — populated as valid reports are confirmed. Structure: Name/handle · date · summary of the class of issue (no exploit detail). -->
No public acknowledgments yet.
8. Contact
security@cinta-ai.com · in-product /report · security.txt
Draft v0.9 — pending review by licensed counsel before production use. Last updated: 2026-07-07 (draft).
