Last updated: August 13, 2026
Vulnerability Disclosure
Cedar AI Agents, Inc. ("Cedar") takes the security of our platform and our customers' data seriously. We welcome reports from security researchers and anyone who discovers a potential vulnerability in our systems, and we are committed to working with you to verify and resolve issues quickly.
How to Report
Please email privacy@getcedar.ai with a description of the issue. To help us respond quickly, include where possible:
- A description of the vulnerability and its potential impact
- Steps to reproduce it, including any URLs, requests, or accounts involved
- Any proof-of-concept code, screenshots, or logs
You do not need an existing relationship with Cedar to submit a report.
Scope
This policy covers Cedar's production services, including the Cedar web application and getcedar.ai. If you are unsure whether something is in scope, report it and we will let you know.
The following are outside the scope of this policy:
- Denial-of-service (DoS) attacks or any testing that degrades or disrupts our services
- Social engineering, phishing, or physical attacks against Cedar, our staff, or our customers
- Vulnerabilities in third-party services or software that Cedar does not control
- Reports from automated scanners without a demonstrated, exploitable impact
Safe Harbor
If you make a good-faith effort to comply with this policy during your research, we will consider your activity authorized, and we will not pursue or support legal action against you. To stay within good faith, please:
- Only interact with accounts you own or have explicit permission to test
- Avoid accessing, modifying, or deleting other users' or customers' data
- Stop testing and report immediately if you encounter customer data
- Give us a reasonable amount of time to resolve an issue before disclosing it publicly
Our Commitment
When you submit a report in line with this policy, we will:
- Acknowledge receipt of your report
- Work to validate the issue and keep you informed of our progress
- Remediate confirmed vulnerabilities as quickly as is practical, based on severity
- Credit you for your discovery if you would like, once the issue is resolved
Cedar does not currently operate a paid bug-bounty program, but we are grateful for every responsible disclosure and are happy to acknowledge your contribution.
Contact
Security reports: privacy@getcedar.ai
Cedar AI Agents, Inc., Suite 2700, The Stack, 1133 Melville St, Vancouver, BC V6E 4E5, Canada