TriangleAI welcomes reports from security researchers, customers, and partners who discover potential vulnerabilities in our products and infrastructure.
app.triangl.ai and api.triangl.ai (Tri web application and API)Out of scope: third-party services (AWS, Stripe, etc.), social engineering, physical attacks, and denial-of-service testing without prior written approval.
TriangleAI does not currently offer monetary bug bounty rewards. We may introduce a formal paid bounty program through a third-party platform as we scale. This page constitutes our public coordinated vulnerability disclosure program.
We support responsible disclosure. If you follow this policy and avoid privacy violations, data destruction, and service degradation, we will consider your research authorized.