Skip to content

Security

Found something? Tell us.

Percidian holds the business context its customers' AI systems run on, so a weakness in it is a weakness in their work. If you have found one, we want to hear about it — and we will not come after you for looking, provided you followed the policy below.

Last updated August 17, 2026 · Acknowledged within 5 business days · Safe harbor for good-faith research

Report

Send it here.

Use the form, or email security@percidian.com if you would rather. Both reach the same team.

Fields marked * are required.

Numbered steps, the exact request and response if you have them, and the URL or endpoint you hit. Enough that we can reproduce it without guessing.

What an attacker gets out of it, and what they would need to start with.

Do not paste credentials, customer data, personal data, or anything else you extracted while testing. Describe what you were able to reach; we will open a secure channel for anything that needs to be handed over.

Prefer email? Write to security@percidian.com.

What to include

What makes a report we can act on.

  • What the issue is, and what an attacker gets out of it.
  • How to reproduce it — numbered steps, the affected URL or endpoint, and the request and response if you have them.
  • Anything that helps us see it: a proof of concept, a screenshot, a log excerpt.
  • The name or handle you want to be credited by, if you want credit.

Leave out what you extracted. Do not send credentials, customer data, personal data, or the contents of anything you were able to reach. Describe what you got to; if we need the material itself, we will open a secure channel for it.

For a sensitive report, encrypt it to our key.
Fingerprint: DEF0 239A 68A8 395F DD2D FD3C EBA6 C2F7 0009 C13C
Download the public key

Scope

What you may test, and what you may not.

In scope

  • percidian.comThis site, and percidian.ai, which redirects to it.
  • book.percidian.comThe briefing booking application.
  • Percidian ACE, Gateway and AgentsThe products as deployed for your own organization. Test only against your own tenant, and tell us in the report which tenant it is.

Out of scope

  • trust.percidian.com and any other service Percidian runs on a third-party platform — report those to the platform operator, who can fix them
  • Systems belonging to Percidian customers, partners, or vendors, including any tenant you have not been authorized to test
  • Social engineering of Percidian staff, contractors, or customers, including phishing and pretexting
  • Physical attacks against Percidian offices, staff, or infrastructure
  • Denial of service, volumetric testing, load testing, and anything else that degrades a service others are using
  • Automated scanner output with no demonstrated impact
  • Missing security headers, weak cipher suites, and other best-practice findings without a working exploit
  • Vulnerabilities that only affect end-of-life software or unsupported browsers
  • Clickjacking on pages that take no sensitive action, self-XSS, and issues that need physical access to a victim’s unlocked device
  • Email configuration findings (SPF, DKIM, DMARC) unless you can show a message being delivered as Percidian

If you are unsure whether something is in scope, ask at security@percidian.com before you test it. We would rather answer the question than have you guess.

Safe harbor

Research in good faith, and we will not pursue you.

Percidian will not bring legal action against you, or ask law enforcement to, for security research carried out in good faith under this policy. To be covered by that, you must:

  • Make a genuine effort to avoid privacy violations, data destruction, and any interruption to a service someone else is relying on
  • Only interact with accounts you own, or that the account holder has explicitly permitted you to access
  • Stop at the point the issue is demonstrated — do not pivot, escalate, or collect data beyond that
  • Give Percidian 90 days to remediate before disclosing publicly
  • Stay within the law

If a third party takes action against you for work that followed this policy, we will state publicly that the work was authorized.

This is not permission to test systems that are not ours. Where a Percidian product runs inside a customer’s environment, that environment is the customer’s to authorize, not ours.

What we do

What you get back from us.

  • We acknowledge your report within 5 business days.
  • We tell you what we found when we triage it, and what we intend to do about it.
  • We keep you updated while we fix it, rather than going quiet.
  • We credit you by whatever name you give us once the issue is resolved, if you want the credit.

Rewards

Percidian does not run a paid bounty programme, and we would rather say so plainly than imply otherwise. What we can offer is a fast, human response and public credit in whatever form you ask for.

Coordinated disclosure

We ask for 90 days from the date of your report before you disclose publicly, including to other researchers. If the issue is severe enough that the window is wrong, say so and we will agree a timeline with you rather than hold you to this one.

Questions

Unsure about any of this? Ask before you test.

Email security@percidian.com and we will answer quickly. If you are a customer or prospect running a security review rather than reporting a bug, the Trust Center has the architecture, control and assurance material.

Bring your business into every AI decision

Give every approved AI system the context to do its best work.

Connect the knowledge your organization already has. Preserve what it learns. Apply the permissions it already trusts. Make that understanding available wherever people and agents work.

Request a briefing