# Report a security issue.

> Found a security issue in Scrini AI? How to report a vulnerability safely to support@scrini.ai, what is in scope and what to expect from us.

URL: https://landing.qa.scrini.ai/vulnerability-disclosure  
Breadcrumb: Home > Vulnerability disclosure

Last updated: October 2, 2026. Keeping candidate and customer data safe matters more to us than anything else we build. If you think you have found a vulnerability, we want to hear from you.

[Email support@scrini.ai](mailto:support@scrini.ai?subject=Security)

## How to report

Email support@scrini.ai with "Security" in the subject. Include what you found and where (URL, endpoint or feature), the steps to reproduce it with a proof of concept and the impact you think it has.

## Please do not

- Access, change or delete data that is not yours
- Run tests that slow down or disrupt the service
- Use social engineering, phishing or physical attacks
- Share the issue publicly before we have fixed it

## What you can expect from us

| Step | Timing |
| --- | --- |
| We confirm we got your report | Promptly |
| We assess it and share next steps | Once we have triaged it |
| We fix it and let you know | As fast as severity requires |

## Scope

- In scope: scrini.ai, app.scrini.ai and our public APIs
- Out of scope: third-party services we use and reports from automated scanners without a working proof of concept

## Safe harbor

If you make a good-faith effort to follow this policy, we will treat your research as authorized, we will not pursue or support legal action against you for it and we will work with you to understand and fix the issue. If a third party takes legal action over research that followed this policy, we will make it known that your research was authorized. Our security contact is also published in our security.txt file at /.well-known/security.txt.

## Thank you

With your permission, we are happy to credit you once the issue is fixed.

## Related policies.

### Privacy Policy

How Scrini collects, uses and protects personal data.

[Read](https://landing.qa.scrini.ai/privacy-policy)

### Candidate Privacy Notice

For people assessed through Scrini by an employer.

[Read](https://landing.qa.scrini.ai/candidate-privacy-notice)

### AI Transparency Notice

How our AI agents work and the choices candidates have.

[Read](https://landing.qa.scrini.ai/ai-transparency)

### Cookie Policy

Cookies, consent and how to change your choices.

[Read](https://landing.qa.scrini.ai/cookie-policy)

### Terms of Service

The agreement for using the Scrini platform.

[Read](https://landing.qa.scrini.ai/terms-of-service)

### Acceptable Use Policy

What customers may and may not do with Scrini.

[Read](https://landing.qa.scrini.ai/acceptable-use-policy)

### Data Processing Addendum

Key terms for processing personal data on your behalf.

[Read](https://landing.qa.scrini.ai/dpa)

### Subprocessors

Third parties that process data for Scrini.

[Read](https://landing.qa.scrini.ai/subprocessors)

### Data Security Policy

How we protect data and respond to incidents.

[Read](https://landing.qa.scrini.ai/data-security-policy)

### Refund Policy

Credits, billing disputes and refunds.

[Read](https://landing.qa.scrini.ai/refund-policy)

### Accessibility Statement

Our accessibility commitment and accommodations.

[Read](https://landing.qa.scrini.ai/accessibility)
