Disclosure policy
Tessera welcomes responsible disclosure from security researchers. We do not have a paid bounty program at this stage, но recognize contributions publicly (with permission).
In scope
- tesseraai.io and subdomains
- ledger.tesseraai.io (operator + sponsor dashboards)
- API routes under /api/* on both domains
Out of scope
- Social-engineering of Tessera staff
- Physical-attack vectors
- Denial-of-service testing (please don't)
- Pre-existing publicly-known vulnerabilities in third-party services we use (Supabase, Vercel, Sentry)
Process
- Email security@tesseraai.io with proof-of-concept + impact assessment
- We acknowledge within 48 hours
- We work toward a fix; estimated timeline shared within 7 days
- Coordinated public disclosure after fix deployed (90-day window default)
Safe harbour
Good-faith research conducted under this policy will not be subject to legal action by Tessera. Please act responsibly: do not access more data than necessary to demonstrate impact, do not destroy or modify data, и не disrupt service for others.
Contact: security@tesseraai.io