Responsible disclosure policy — how to report a vulnerability and what to expect from us.
If you have found a security issue in Navige, please email us directly at hello@navige.ai. Do not open a public GitHub issue for security vulnerabilities.
| Target | Examples |
|---|---|
| api.navige.ai | Authentication bypass, tenant data leakage, injection, approval flow manipulation |
| app.navige.ai | XSS, CSRF, session issues |
| navige.ai | Reflected or stored XSS, open redirects |
| Navige SDKs | npm package, Python SDK — logic or security bugs |
We consider security research conducted under this policy to be authorised. We will not pursue civil or criminal action against researchers who discover and report vulnerabilities in good faith and in accordance with this policy. If a third party initiates legal action against you for research you conducted under this policy, we will make clear that your actions were authorised by us.
Email: hello@navige.ai
You can also reach us via the /.well-known/security.txt standard contact file.
Every report we receive is logged with: date received, severity assessment, fix date, and whether it was publicly disclosed. We are building a track record we can share with enterprise customers and auditors.