RESPONSIBLE DISCLOSURE POLICY

Effective date: August 20, 2026

Dirac Labs builds navigation technology for platforms that cannot afford to fail, and we take security seriously — including the security of our public web presence. We welcome good-faith security research and will work with researchers who follow this policy.


1. SCOPE

In scope:
- www.diraclabs.com and diraclabs.com
- Subdomains of diraclabs.com operated by Dirac Labs

Out of scope:
- Third-party platforms and infrastructure we use but do not operate, including Webflow (hosting), Squarespace (DNS), Google Workspace, and Cloudflare. Please report issues in those platforms to their respective security programs.
- Any form of denial-of-service or load testing
- Social engineering, phishing, or physical attacks against Dirac Labs personnel, offices, or partners
- Spam, SPF/DKIM/DMARC configuration reports without a demonstrated exploit, clickjacking on pages with no sensitive actions, and other non-exploitable best-practice findings


2. RULES OF ENGAGEMENT

When researching, you must:
- Avoid privacy violations: do not access, modify, or exfiltrate data belonging to Dirac Labs or third parties. If you encounter personal data, stop and report immediately.
- Not degrade or disrupt our services
- Not use automated scanners at high volume
- Use only your own accounts and data in testing
- Give us a reasonable opportunity to remediate before any public disclosure


3. HOW TO REPORT

Email security@diraclabs.com with:
- A description of the vulnerability and its potential impact
- Step-by-step instructions to reproduce it (proof-of-concept where possible)
- The URL or component affected
- Your name or handle if you would like public credit

Please report in English. We ask that you do not share the report with anyone else until we have resolved the issue.


4. WHAT WE PROMISE

- We will acknowledge your report within 5 business days.
- We will keep you informed of our progress and tell you when the issue is resolved.
- We will credit you for the discovery on request, once the issue is fixed, unless you prefer to remain anonymous.
- We do not currently operate a paid bug bounty program.


5. SAFE HARBOR

We will not initiate or support legal action against you for security research conducted in good faith and in accordance with this policy. This includes research that involves a good-faith violation discovered accidentally, provided you report it promptly and follow the rules above. This safe harbor does not apply to research that violates the rights of third parties, and we cannot authorize testing of third-party systems on your behalf.


6. CONTACT

security@diraclabs.com
Dirac Labs Inc., Madison, WI, United States
Dirac Labs UK Ltd., 5 New Street Square, London, EC4A 3TW, United Kingdom