Skip to content
embirolabs
ModelsPlatformDevelopersWhy Africa
Join waitlist
Legal & trust / Security & responsible disclosure

Security & responsible disclosure

Found something that needs attention? Help us put it right.

Effective 11 October 2026 · Version 1.1

On this page

01Current website safeguards02What to send03Responsible testing boundaries04How we handle reports05Account safety and incidents06Before production workloads
Questions? Talk to us ↗

This page explains current website safeguards and a responsible way to report issues. It is not a security certification, warranty or paid bug-bounty programme.

Current website safeguards

The waitlist uses HTTPS, server-side schema validation, request size limits, same-origin checks, signed forwarding to the designated backend, short-lived one-use questionnaire permissions and hourly abuse controls. Raw questionnaire tokens are not stored in the database.

Email delivery uses an outbox with per-message identifiers and retry coordination. Server-side credentials are kept out of public client code. These measures reduce specific risks; they do not mean every attack is prevented or every component has undergone an independent audit.

What to send

Email collins@embiro.ai with the subject “Embiro Labs security report”. Include the affected URL or component, a short description, the approximate time with time zone, safe reproduction steps, the impact you observed and a way to contact you.

Redact personal data and secrets from screenshots or logs. Do not email live credentials, large datasets or other people’s private records. If evidence is sensitive, first ask us to arrange an appropriate transfer method.

Responsible testing boundaries

Limit investigation to what is necessary to explain a potential issue in Embiro-operated application behaviour. Stop if you encounter other people’s data. Do not retain, alter, export or delete it. Avoid denial-of-service testing, spam, social engineering, physical intrusion or actions that impair service.

Do not test Vercel, OpenAI, Cloudflare, Resend or other third-party infrastructure without their authorisation. This invitation to report is not permission to bypass laws, access controls or provider rules, and is not a blanket safe-harbour commitment.

How we handle reports

We review reports, ask for clarification where needed, assess risk and work on an appropriate response. There is no guaranteed response or remediation service level for this pre-launch site. If you have not heard back, follow up in the same email thread.

We ask you to avoid public disclosure of exploit details or personal information while a fix is being assessed. If you would like acknowledgement, tell us how you prefer to be credited; credit and payment are not guaranteed.

Account safety and incidents

We will not ask you to reply with a password, API key or authentication code. Check links and sender details. Platform uses invited accounts with email codes and passkeys. Application API keys are real credentials: keep them server-side and revoke a compromised key promptly.

For a suspected personal-data incident, contact us promptly with minimal necessary details. We will assess applicable reporting duties and notifications. Serious incidents are communicated plainly; promotional language and illustrations are secondary to accurate instructions.

Before production workloads

Authentication, access controls, inference routing, data retention, incident processes and operational assurances for a future live platform will be described before onboarding. We do not claim ISO 27001, SOC 2, a particular uptime percentage or an independent penetration-test result on the basis of this website.

A real person, a real address.

Embiro Labs
4 Norfolk Gardens, Kyambogo
Kampala, Uganda
collins@embiro.ai
Privacy notice ↗Terms of use ↗Acceptable use ↗Cookies & storage ↗Service providers ↗Communication preferences ↗
embirolabs

Intelligence,
closer to home.

Model cataloguePlatformDeveloper toolsAfrican hostingJoin the waitlistBrand & press
© 2026 Embiro Labs
An Embiro company Legal & trustPrivacyTermsCookies