Thank you
Every name on this page belongs to someone who chose to tell us about a weakness rather than exploit it or sell it. That choice is the foundation the whole platform rests on. Vortalis sells the claim that an independent party can verify what an AI agent did and that sensitive data is shielded by default. A researcher who tests that claim and reports honestly is doing the exact work the product asks the world to do. We are grateful, and we say so in public.
How we credit researchers
When a report is confirmed and a fix has shipped, we add the researcher to the list below with their preferred name or handle, the month of disclosure, and a short, non-sensitive description of the class of issue. We never publish details that would help someone attack a customer, and we never publish a finding before the fix is deployed. If you would rather remain anonymous, tell us in your report and we will record the contribution without naming you. Credit is the only reward we offer; Vortalis does not currently run a paid bug-bounty programme, and we are honest about that in the disclosure policy.
The list
No external vulnerabilities have been disclosed and confirmed yet. This is the honest state of the page at launch, not a placeholder we forgot to fill in. We would rather publish an empty list truthfully than invent names to look established. As researchers report issues under our coordinated-disclosure policy and we ship the fixes, this section will grow, with the most recent confirmed contributions listed first.
How to be listed here
Follow the responsible-disclosure policy at /security/responsible-disclosure. Report your finding to security@vortalis.ai with enough detail for us to reproduce it. Act in good faith within the scope and safe-harbour terms set out in that policy. Once we have confirmed the issue and deployed a fix, we will ask you how you would like to be credited and add you here. There is no form to fill in and no points system to game; a single well-described, reproducible report that leads to a real fix is exactly what earns a place on this page.
What we will not do
We will not quietly fix a reported issue and leave the researcher uncredited unless they asked to remain anonymous. We will not dispute credit to avoid acknowledging that a vulnerability existed. We will not use this page to imply a finding was less serious than it was. The same honest-framing discipline that governs the rest of the Vortalis site governs this page: it reflects what actually happened, and it is maintained as the platform evolves rather than frozen at launch.
To be listed here, report a vulnerability under our responsible-disclosure policy. We credit every confirmed contribution once the fix has shipped, unless you ask to remain anonymous.
Read the disclosure policy