Vulnerability Disclosure Policy
Last updated: August 26, 2026
Effective date: August 26, 2026
Reporting
Email security@casola.ai. We acknowledge within five business days, and we tell you what we decided and when it is fixed.
Scope
The Casola platform: www.casola.ai, app.casola.ai, api.casola.ai, admin.casola.ai and
docs.casola.ai, the embed we serve to customer sites (/embed.js), the published
@casola/avatar-client SDK, and the live-session protocol between a browser and our
infrastructure.
Products built on Casola run on their own codebases and are looked after by their own teams. Send those findings here regardless; we pass them to whoever owns the surface, so you do not have to work the boundary out yourself. What this policy authorizes is testing the platform described above — testing one of those products is covered by that product’s own policy.
Not in scope: anything not named above, our vendors’ own systems, and anything needing physical access to a device or social engineering of our staff. Non-production copies of the platform are deliberately more permissive and hold no real data, so a finding against one says nothing about the product. Test production.
Authorization
We will not pursue legal action against, or report to law enforcement, anyone researching in good faith who follows this policy, and if a third party brings a claim about research that followed it, we will state that the research was authorized. Our Acceptable Use Policy prohibits unauthorized access; Section 2 carves out research that follows this policy, and we will not close an account over it. Good faith means what is below.
What we ask
Test against your own account and your own workspace. Ask us for one if you need it — we would rather give you access than have you work around it.
Stop once you have confirmed a problem. Do not read, change, or retain anyone else’s data. A session carries conversation, recording and transcript that belong to someone.
No load testing or automated scanning against the session API. Every live session takes a seat on a shared GPU fleet, so volume testing takes the product down for real people rather than proving anything. Open the sessions your test needs, then release them.
Give us reasonable time to fix something before writing about it publicly. Ninety days is the usual figure.
We do not pay for reports. We are glad to credit you if you would like that.
security@casola.ai for anything on this page. Casola, 440 N. Wolfe Rd, Sunnyvale, CA 94085.