Legal
Security
If you think you have found a security problem in anything we run, email team@sarala.ai. We would rather hear about it early and from you.
Reporting an issue
Send a message to team@sarala.ai with the word “Security” in the subject line. Please include:
- what you found and where (the address or feature involved);
- the steps to reproduce it, as plainly as you can;
- what you think an attacker could do with it.
The same details are published in machine-readable form at /.well-known/security.txt. Please do not include real personal data of other people in a report. If you have to prove access, describe it rather than copying the data.
What is in scope
- The websites at sarala.ai and getapex.dev.
- The APEX Community cockpit and the services behind it, which we run.
Not in scope: other people’s organisations, cloud projects, repositories or model accounts that someone has connected to the cockpit, and third-party services we use (report those to the provider). Weaknesses in code that a user chooses to run inside their own sandbox are that user’s own business, unless they let you reach another user or our systems.
Ground rules
We will not take legal action against research that follows these rules and is carried out in good faith:
- Test only against accounts and organisations you own or have permission to use.
- Do not read, change or delete other people’s data. Stop as soon as you have shown the problem.
- No denial-of-service testing, no spam, and no social engineering of our team or users.
- Give us a reasonable chance to fix the issue before you publish details.
What happens next
- We aim to acknowledge your report within 72 hours.
- We will tell you whether we can reproduce it, and keep you informed until it is fixed.
- If you would like to be credited once it is fixed, tell us how. We do not run a paid bounty programme at present.
Responsible use of compute
Running code in sandboxes and running agents costs real money and shares real machines with other people. We treat it as a limited resource, and abuse of it as a security matter.
- Do not use the service for cryptocurrency mining, spam or phishing, scanning or attacking other systems, generating floods of traffic, or running a public service or proxy from a sandbox.
- Do not try to get around limits or to break out of a sandbox. If you find a way, report it to us instead of using it.
- We may look at run metadata, such as timing and resource use, to detect abuse. We may throttle, pause or stop runs, and suspend an organisation straight away, without notice, to protect the platform and other users.
- To report abuse of the service, email team@sarala.ai. The full rules are in the Terms of Service.
How we approach security
Security follows the same rule as the rest of what we build: keep it simple enough to inspect.
- This website is static. It sets no cookies, runs no analytics, loads nothing from third parties, and is served with a strict content security policy.
- Everything is served over HTTPS.
Privacy questions belong in our Privacy Policy; the rules for using the service are in the Terms of Service.