Trust / Security
Protect the mission. Report the weakness.
Unified Mechanics welcomes responsible reports that help strengthen our public digital systems. This policy defines where research is authorized, how to report safely, and what researchers can expect from us.
Security contact
contact@unifiedmechanics.aiUse “Security Report” in the subject line. If ordinary email would expose sensitive material, send a high-level notice first and request an appropriate channel.
Submit a reportPublic digital assets
Good-faith research
Coordinated disclosure
Purpose and principles
Security is part of mission reliability. We value researchers who identify credible weaknesses, minimize risk while validating them, and give us a reasonable opportunity to investigate before information is disclosed publicly.
This policy applies only to good-faith research involving the public digital assets listed below. It does not authorize access to operational, customer, partner, prototype, vehicle, weapon, facility, or personnel systems.
Systems in scope
Research is in scope when it concerns a publicly accessible digital asset that Unified Mechanics owns and operates, including:
- Websites and web applications on unifiedmechanics.ai and its public subdomains.
- Public APIs or internet-facing services that explicitly identify Unified Mechanics as the operator.
- A vulnerability in a third-party dependency when the report includes a reproducible, material impact on an in-scope Unified Mechanics asset.
- A configuration issue that creates demonstrable unauthorized access, exposure, or loss of integrity on an in-scope asset.
If ownership or scope is unclear, contact us before testing. Absence from the list above should be treated as out of scope.
Out of scope
The following systems and activities are not authorized under this policy:
- Aircraft, interceptors, launch systems, radar, sensors, radios, embedded hardware, prototypes, test equipment, or other physical products.
- Operational technology, command-and-control environments, mission networks, customer systems, government systems, partner infrastructure, or deployed environments.
- Employee devices, offices, facilities, access controls, wireless networks, vendors, suppliers, or personal accounts.
- Denial-of-service activity, traffic flooding, resource exhaustion, destructive testing, malware, persistence, or any action that could impair availability.
- Social engineering, phishing, impersonation, physical intrusion, credential stuffing, password spraying, brute force, or testing with stolen credentials.
- Automated scans that generate substantial traffic; simple port scans; banner reports; missing headers; weak-cipher notices; self-XSS; or clickjacking without a credible security impact.
- Third-party services with no reproducible impact on a Unified Mechanics-owned asset, and vulnerabilities already publicly disclosed or already known to us.
Rules of engagement
To remain within this policy, research must be proportionate, non-disruptive, and limited to what is necessary to demonstrate the issue.
- Use accounts and data you own, or for which you have explicit permission.
- Do not alter, delete, encrypt, corrupt, retain, publish, or distribute data that does not belong to you.
- Do not pivot beyond the original finding, establish persistence, exfiltrate data, or access additional records once the issue is demonstrated.
- Do not degrade performance, interrupt service, affect another user, or create safety, privacy, legal, export-control, or operational risk.
- Do not use a vulnerability to seek payment, threaten disclosure, or demand commercial terms.
- Comply with applicable law and stop immediately if there is any risk to people, property, missions, or third-party systems.
Sensitive information
Do not transmit classified information, controlled unclassified information, export-controlled technical data, credentials, private keys, personal data, customer data, mission data, or operational details through this website or ordinary email.
If sensitive information is encountered unintentionally, stop testing, do not access additional material, preserve only the minimum evidence needed to identify the issue, and notify us with a high-level description. We will coordinate an appropriate channel if more detail is required.
How to report
Email contact@unifiedmechanics.ai with “Security Report” in the subject line. A useful report includes:
- The affected domain, endpoint, service, feature, or software version.
- A clear description of the vulnerability and its likely security impact.
- Minimal, repeatable steps to reproduce the behavior, including relevant requests or screenshots.
- The date and time observed, testing source IP if you are comfortable providing it, and any conditions required to reproduce.
- Whether any data was accessed and, if so, the smallest possible description of its type and quantity.
- Your preferred name, contact method, and any disclosure timeline you are considering.
Please submit one vulnerability per report unless multiple findings are required to demonstrate a single impact.
Our commitments
For reports submitted in accordance with this policy, Unified Mechanics will aim to:
- Acknowledge receipt within five business days and identify a point of contact when follow-up is needed.
- Review the report, validate impact, and request only the additional information needed for investigation.
- Provide reasonable status updates as triage and remediation progress, subject to operational and legal constraints.
- Prioritize remediation based on exploitability, impact, affected data, and risk to users or operations.
- Recognize the reporter when appropriate and mutually agreed. We will not publish a researcher’s identity without permission.
Response and remediation timelines vary with complexity. This policy does not guarantee a particular resolution date or compensation.
Coordinated disclosure
Please allow at least 90 days after the initial report before public disclosure, or a different timeline agreed with us in writing. Some issues may require more time because of dependency coordination, customer obligations, operational constraints, or the need to deploy a fix safely.
Do not share exploit details, proof-of-concept code, affected data, or information that would materially increase risk while remediation is underway. We will work in good faith toward a disclosure plan that protects users and gives the research appropriate context.
Safe harbor
When research is conducted in good faith and in accordance with this policy, Unified Mechanics will consider it authorized with respect to applicable anti-hacking and anti-circumvention laws under our control. We will not initiate or support legal action for accidental, good-faith violations that are promptly reported and corrected.
This safe harbor is limited to claims controlled by Unified Mechanics. It does not bind third parties, authorize violation of law or third-party agreements, grant access to government or customer systems, or waive rights unrelated to the research described here. If you are uncertain whether a test is permitted, contact us before proceeding.
Policy terms and updates
Participation is voluntary and at the researcher’s own risk. This policy does not create an employment, agency, partnership, procurement, or contractual relationship, and it does not grant intellectual-property rights or permission to use Unified Mechanics names, marks, or confidential information.
We may update this policy as our public systems and security practices evolve. The version published on this page governs research performed after its effective date. For questions about scope or interpretation, contact us before testing.
Found something credible?