CoreShieldCoreShield AI

Security at CoreShield

CoreShield AI is a privacy product. Security is not a feature bolted on — it is the architecture. Here is how we protect the data you trust us with, and how to reach us if you find a flaw.

How your data is protected

Reporting a vulnerability

Found a security issue? Please do not open a public issue. Email us with a description, impact assessment, and reproduction steps, and we will work with you on a coordinated disclosure.

security@maincore.sa
  • We acknowledge every report within 24 hours.
  • We return a triage decision within 72 hours.
  • We ask for 90 days of coordinated disclosure before public write-ups.
  • Reports in Arabic are welcome at the same address.

In scope

All CoreShield services, applications, packages, infrastructure manifests, and the deployed platform at app.coreshield.dev.

Out of scope

Social engineering, physical attacks, denial-of-service and volumetric testing, and third-party providers (report those to them directly).