Skip to main content

Trust

Vulnerability Disclosure Policy

Last updated June 29, 2026. We welcome reports from security researchers and treat good-faith research as a help, not a threat.

In short

Found a security issue in Standard Works? Email security@standardworks.ai. Give us a reasonable chance to fix it before disclosing publicly, don't access more data than you need to prove the issue, and we won't pursue legal action against your good-faith research.

Scope

This policy covers the services and domains operated by Standard Works (a product of Efex AI, Inc.), including:

  • standardworks.ai and the application at app.standardworks.ai
  • The Public Archives product and its document collections
  • Our public APIs and supporting infrastructure

How to report

Email security@standardworks.ai. To help us triage quickly, please include:

  • A clear description of the vulnerability and its potential impact.
  • Step-by-step instructions to reproduce it, including any proof-of-concept.
  • The affected URL, endpoint, or component, and the date and time of your testing.
  • Your name or handle, if you'd like to be credited.

What we commit to

  • Acknowledge your report within 3 business days.
  • Triage and validate the issue and give you an initial assessment within 10 business days.
  • Keep you updated on our remediation progress and let you know when the issue is resolved.
  • Credit you for the discovery if you wish, once a fix is in place.

What we ask of you

  • Give us a reasonable time to remediate before disclosing the issue publicly.
  • Make a good-faith effort to avoid privacy violations, data destruction, and interruption or degradation of our services.
  • Only interact with accounts you own or have explicit permission to access. Do not access, modify, or retain more customer data than is necessary to demonstrate the vulnerability.
  • Do not use automated scanning that generates excessive traffic, social engineering, physical attacks, or denial-of-service techniques.

Safe harbor

We consider security research and vulnerability disclosure conducted in accordance with this policy to be authorized, beneficial, and conducted in good faith. We will not pursue or support legal action against you for accidental, good-faith violations of this policy, and we will not report your activity to law enforcement provided you comply with it.

To the extent your activity is consistent with this policy, we waive any relevant restriction in our Terms of Service that would otherwise prohibit it, solely for the purpose of your good-faith security research. If you are unsure whether a specific action is authorized, email us first at security@standardworks.ai and we'll be glad to clarify.