Fieldwork AI Inc.
Vulnerability Disclosure Policy
How to report a security vulnerability to Fieldwork, and what to expect.
Last updated: 14 September 2026
Fieldwork AI Inc. ("Fieldwork", "we", "us") welcomes reports from security researchers and users who find a vulnerability in our service, our website or our open-source projects. This policy explains what is in scope, how to report, what you can expect from us, and what we ask of you.
Scope
- The Fieldwork service at app.getfieldwork.ai and its APIs.
- Our desktop, mobile and command-line clients.
- Our website at getfieldwork.ai.
- Our open-source projects under github.com/fieldwork-ai.
Out of scope: third-party services we use but do not operate (for example our cloud, model and connectivity providers), our customers' own systems, and findings that require physical access to a device or social engineering of our personnel or customers.
How to report
Email security@getfieldwork.ai with enough detail to reproduce the issue: the affected component, steps to reproduce, and the impact you believe it has. For our open-source projects you may instead use GitHub's private vulnerability reporting on the relevant repository. Our contact details are also published at /.well-known/security.txt.
What you can expect from us
- We will acknowledge your report within five business days.
- We will keep you informed as we investigate and remediate, and we will tell you when the issue is resolved.
- We will not take legal action against you for research conducted in good faith and within this policy.
- We will credit you publicly if you would like us to, once the issue is fixed.
We do not currently run a paid bug bounty programme.
What we ask of you
- Do not access, modify or delete data that is not your own. If you encounter another customer's data, stop and report it.
- Do not degrade the service: no denial-of-service testing, spam or resource exhaustion.
- Do not use social engineering, phishing or physical attacks.
- Give us a reasonable time to fix the issue before disclosing it publicly, and coordinate the timing with us.
- Comply with applicable law.
Safe harbour
Research that follows this policy is authorised. We consider it a good-faith effort to improve our security, and we will not pursue or support legal action against you for it. If a third party takes action against you for research that complied with this policy, we will make it known that your activity was authorised.