> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fortytwo.network/llms.txt
> Use this file to discover all available pages before exploring further.

# Vulnerability Disclosure Policy

**Effective date:** 3 October 2026

## 1 Introduction

Fortytwo MENA Limited, incorporated in Abu Dhabi Global Market, Abu Dhabi, United Arab Emirates, with registration number 36387 ("Fortytwo", "we", "us"), welcomes reports of security vulnerabilities in our services. This Policy explains what you may test, how to report what you find, what you can expect from us, and how we treat research carried out under it.

If you believe you have found a vulnerability, please report it to us privately and give us a reasonable opportunity to fix it before you share it with anyone else.

## 2 Scope

This Policy covers:

* the Fortytwo API at api.fortytwo.network;
* the Fortytwo console at platform.fortytwo.network;
* our documentation at docs.fortytwo.network;
* our websites at fortytwo.network and harbor.fortytwo.network; and
* public artefacts we publish, such as container images, software packages, public source repositories, and published model files, including any secrets or credentials exposed in them.

Anything not listed is out of scope. Systems operated by our providers, such as payment, hosting, or email providers, are out of scope unless the vulnerability is caused by how we have integrated or configured them. If you are unsure whether something is in scope, ask us first at [security@fortytwo.network](mailto:security@fortytwo.network).

We are especially interested in:

* access to another customer's prompts, outputs, files, API keys, account, or billing data, including through caches or shared infrastructure;
* authentication, authorisation, or session weaknesses;
* ways to bypass billing, credit balances, quotas, or rate limits;
* server-side request forgery or code execution through any feature of the Services; and
* secrets or credentials exposed in our public artefacts.

## 3 Out of scope

The following are not eligible under this Policy:

* model behaviour, such as jailbreaks, harmful, biased, or inaccurate output, and prompt injection that affects only your own requests; please report these as described in Section 9 instead;
* limitations inherent to third-party or open-weight models we serve, which should be reported to the model's developer;
* denial-of-service, load, or volume testing, and resource exhaustion through very large or repeated requests;
* social engineering, phishing, or physical attacks against our staff, offices, or providers;
* reports about rate limiting or brute force without demonstrated impact;
* missing security headers, SPF, DKIM, DMARC, or CAA records, TLS configuration, or version disclosure, without a demonstrated exploit;
* clickjacking on pages without sensitive actions, self-XSS, CSRF on logout or unauthenticated forms, and open redirects without further impact;
* account or email enumeration without further impact;
* API keys or credentials that a customer has exposed themselves;
* unvalidated output from automated scanners; and
* vulnerabilities in third-party software that were made public less than 30 days before your report.

## 4 How to report

Report vulnerabilities through "Report a security issue" in the Fortytwo console, or by email to [security@fortytwo.network](mailto:security@fortytwo.network). Use email if you need to share files, videos, or logs, and put a short title in the subject.

Please include:

* the affected host, endpoint, or artefact;
* a description of the issue and its potential impact;
* the steps needed to reproduce it, with a proof of concept where possible; and
* any account or request identifiers that help us find the relevant records.

Please do not include other people's personal data, real API keys, or other secrets unless they are essential to show the issue, and redact them where you can. You may report anonymously, but then we may not be able to follow up with you. Reports in English are preferred.

## 5 Rules for testing

When testing, you must:

* test only against accounts, organisations, and API keys that you own or have explicit permission to use;
* use no more access than you need to confirm the vulnerability, and not keep, copy, change, or delete data that does not belong to you;
* stop testing and tell us immediately if you encounter another customer's data, such as prompts, outputs, keys, or billing information, and not share it with anyone;
* not install persistent access, move to other systems, or use a vulnerability beyond what is needed to demonstrate it;
* keep automated testing at a low rate that does not degrade the Services for others;
* not carry out any of the activities listed as out of scope in Section 3;
* not attempt to extract, reconstruct, or exfiltrate model weights, the inference engine, ranking or routing logic, or other proprietary components; if you believe such an extraction is possible, report the method without carrying it out;
* keep information about the vulnerability confidential until it is resolved or the disclosure period in Section 7 has passed; and
* not demand payment or any other benefit in exchange for not disclosing a vulnerability.

## 6 What you can expect from us

When you report under this Policy, we will:

* acknowledge your report within three business days;
* give you our initial assessment within ten business days;
* keep you informed of our progress at least every 30 days until the issue is resolved;
* tell you when the issue has been fixed; and
* with your permission, credit you publicly for the discovery.

We do not currently offer monetary rewards for vulnerability reports.

## 7 Coordinated disclosure

We ask you to give us 90 days from your report to fix a vulnerability before you disclose it publicly. We may agree a shorter period if we fix the issue sooner, or ask for a longer one if a fix is complex; we will explain why. If a vulnerability is being actively exploited, we will work with you on an earlier timeline. We may publish our own notice about a resolved vulnerability and will coordinate its timing and content with you. Where a law requires us to report a vulnerability to a public authority, we may do so before the disclosure period ends; this does not change our commitments to you under this Policy.

## 8 Safe harbour

If you make a good-faith effort to comply with this Policy during your research, we consider that research to be:

* authorised with respect to applicable anti-hacking laws, and we will not initiate or support legal action against you for accidental, good-faith violations of this Policy;
* authorised with respect to applicable anti-circumvention laws, and we will not bring a claim against you for circumventing technology controls;
* exempt from restrictions in our [Terms of Service](/legal/terms-of-service) that would interfere with security research carried out under this Policy, including restrictions on evading technical safeguards and rate limits, which we waive on a limited basis for that purpose only; and
* lawful, helpful to the security of the Services, and conducted in good faith.

This exemption does not extend to the restrictions in our Terms of Service on reverse engineering or extracting our proprietary software, model weights, or trade secrets. Research that attempts such extraction is not authorised under this Policy.

You must still comply with all applicable laws. This safe harbour applies only to legal claims that we control. It cannot bind public authorities, such as prosecutors, in any jurisdiction, or independent third parties, including our providers. If a third party brings legal action against you in connection with research that complied with this Policy, we will make it known that your actions were conducted in compliance with it.

If you are unsure whether a specific test is consistent with this Policy, ask us at [security@fortytwo.network](mailto:security@fortytwo.network) before you carry it out.

## 9 AI safety and abuse reports

Reports about how models behave, such as jailbreaks, harmful or unsafe output, or misuse of the Services by others, are not security vulnerabilities under this Policy. Please report them through "Report a security issue" in the Fortytwo console, choosing "Model behavior and AI safety", or by email to [security@fortytwo.network](mailto:security@fortytwo.network) with "AI safety:" at the start of the subject, so that the right people review them. If you encounter child sexual abuse material, do not download or share it; report it to us immediately and to the appropriate authorities.

If a model-behaviour issue also crosses a security boundary, for example if prompt injection lets you access another customer's data, report it as a vulnerability under this Policy.

## 10 Your information

We handle the information you send us in a report as described in our [Privacy Policy](/legal/privacy-policy). If a report concerns a provider's systems, we may share its technical content with that provider, with your identifying details removed unless you agree otherwise.

## 11 Changes to this Policy

We may update this Policy from time to time and will revise its effective date when we do. Research is governed by the version in force when the research was carried out.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.