Supermemory·Legal
Responsible Disclosure Policy
Overview
Supermemory takes the security of our Services and user data seriously. This Responsible Disclosure Policy explains how security researchers and users can report suspected vulnerabilities to us in a safe, coordinated, and constructive way.
If you believe you have found a security vulnerability in Supermemory, please report it promptly and give us a reasonable opportunity to investigate and remediate it before publicly disclosing details.
Reporting a Vulnerability
Please email vulnerability reports to dhravya@supermemory.com.
Include enough information for us to reproduce and understand the issue, such as:
- A clear description of the vulnerability and its potential impact
- The affected product, endpoint, domain, repository, or integration
- Steps to reproduce, proof-of-concept code, screenshots, or logs, where safe to share
- Any accounts, workspaces, or test data used during your research
- Your preferred contact information for follow-up
Do not include sensitive personal data, secrets, access tokens, or customer content unless it is strictly necessary to demonstrate the issue.
Scope
This policy applies to security vulnerabilities affecting Supermemory-operated services, including:
- Supermemory web applications and dashboards
- Supermemory APIs and hosted infrastructure
- Official Supermemory integrations, connectors, and plugins
- Authentication, authorization, data access, and data isolation controls
- Public repositories owned by Supermemory, where the issue affects Supermemory users or infrastructure
Third-party services, platforms, and dependencies are only in scope where the vulnerability is caused by Supermemory's implementation or configuration.
Research Guidelines
When conducting research, you agree to:
- Use only accounts, workspaces, data, and systems that you own or are authorized to test
- Avoid accessing, modifying, deleting, or exfiltrating data that does not belong to you
- Stop testing and notify us immediately if you encounter non-public user data, secrets, credentials, or internal systems
- Avoid service degradation, spam, social engineering, phishing, physical attacks, or denial-of-service testing
- Comply with applicable laws and this policy
Out of Scope
The following are generally out of scope unless they demonstrate a concrete, exploitable security impact:
- Automated scanner output without validation or a practical attack path
- Missing security headers or cookie flags that do not create a meaningful exploit
- Clickjacking on pages without sensitive actions
- Rate limiting, brute force, or account enumeration reports without material impact
- Self-XSS, logout CSRF, or issues requiring unlikely user interaction
- Publicly disclosed vulnerabilities in third-party software without evidence that Supermemory is affected
- Denial-of-service, load testing, spam, phishing, social engineering, or physical security testing
Our Commitments
When you follow this policy, we will make a good faith effort to:
- Acknowledge receipt of your report within a reasonable timeframe
- Review the report and ask clarifying questions where needed
- Validate, prioritize, and remediate confirmed vulnerabilities based on severity and risk
- Keep you informed of meaningful status changes when appropriate
- Credit you for responsible disclosure if you request recognition and disclosure is appropriate
Confidentiality
Please keep vulnerability details confidential until we have investigated and addressed the issue. Public disclosure should be coordinated with Supermemory and should not include user data, secrets, exploit code that enables active abuse, or information that would materially increase risk to users.
Rewards
Supermemory does not currently operate a public bug bounty program and does not guarantee monetary rewards for vulnerability reports. We may, at our sole discretion, provide recognition or other thanks for high-quality reports.
Safe Harbor
We will not initiate legal action against security research conducted in good faith, in accordance with this policy, and without harm to Supermemory, our users, or third parties. This safe harbor does not apply to activity that violates the law, causes service disruption, accesses or discloses data without authorization, or exceeds the scope and guidelines in this policy.
Contact Information
For security vulnerability reports, contact us at:
Email: dhravya@supermemory.com
Last Updated: July 11, 2026