4Degrees AI Connector

Security & vulnerability disclosure

We welcome reports from security researchers and customers. This page covers how to report a vulnerability in the 4Degrees AI Connector and the 4Degrees Slack app, what is in scope, and what you can expect from us. It supplements the platform-wide security commitments in our master 4Degrees Privacy Policy.

Effective April 27, 2026

How to report #

Email security@4degrees.ai with a description of the issue, the affected URL or surface, and steps to reproduce. Please do not disclose the issue publicly until we have had a chance to investigate and remediate. We accept reports in English.

Scope #

This disclosure programme covers all 4Degrees production systems, explicitly including:

Out of scope: findings that require physical access, social engineering of 4Degrees staff, denial-of-service / volumetric testing, and reports against third-party services we use (report those to the respective provider — see our sub-processors).

Our response commitment #

Safe harbor #

We will not pursue legal action against researchers who act in good faith, test only against their own account / a test workspace, avoid privacy violations and service disruption, and give us a reasonable opportunity to remediate before any disclosure. This is a coordinated-disclosure programme; we do not currently operate a paid bug-bounty.

Security posture #

Contact #

Security reports and questions: security@4degrees.ai.