Vulnerability Disclosure Policy

Last updated July 14, 2026

Librarian, Inc. ("we", "us") is committed to the security of our customers, partners, staff, and the broader Internet community. We welcome reports of potential security vulnerabilities and follow a coordinated disclosure process to remediate issues efficiently.

1. Scope

In scope:

Out of scope:

2. How to report

Email reports to security@thelibrarian.io. Please include:

Where possible, please use the Common Vulnerability Scoring System (CVSS) to estimate severity. If your report concerns a sensitive matter, you may request that we use PGP - contact us first to exchange keys.

3. Our commitments to you

When you report a potential vulnerability in good faith:

4. What we ask of you

We rely on responsible disclosure to keep our users safe. Please:

5. Rewards

We do not currently operate a paid bug-bounty program. We will publicly acknowledge confirmed reporters (with consent) in our release notes or a security acknowledgments page.

6. Governance

This policy is owned by the senior management team of Librarian, Inc. and reviewed at least annually. Day-to-day staff are trained on this policy and the associated response procedure.

7. Contact

Vulnerability reports: security@thelibrarian.io Privacy questions: privacy@thelibrarian.io General support: support@thelibrarian.io

Postal: Librarian, Inc., 720 Seneca St Ste 107 PMB 79, Seattle, WA 98101, United States

Focus on what really matters

Your time is your most valuable asset. Ready to Save Time with The Librarian?