// scope
This policy covers websites and services owned and operated by empowered.guru, LLC. Third-party services we link to, customer systems we do not control, and components merely embedded from a third party are out of scope unless empowered.guru directly controls the affected component.
Last updated: August 16, 2026
We welcome good-faith security research.
If you believe you found a vulnerability in an empowered.guru-owned system, report it privately so we can investigate and coordinate a responsible resolution.
1. Good-faith research
We consider security research a contribution to the safety of the people who use our work, and we treat good-faith researchers as partners, not adversaries. This page describes how to report to us safely, what we will do, and the safe harbor we offer for good-faith work.
2. Reporting a vulnerability
Send your report to security@empowered.guru. Please include enough detail for us to understand and reproduce the issue:
- The affected URL, service, or component.
- A clear description of the issue and its potential impact.
- Reproduction steps, screenshots, or a minimal proof of concept.
- Any conditions required to reproduce the behavior.
- Your preferred contact details and whether you would like public credit.
If the report includes sensitive data you found (for example, another person's records), do not include it in the report. Send only the proof-of-concept and a redacted reference.
3. The process
Report
Send the smallest useful reproduction privately.
Validate
We review scope, impact, and the safest next step.
Coordinate
We work toward remediation and responsible disclosure.
4. Research guidelines
To keep research safe and constructive, please:
- Use only accounts and data you own or have explicit permission to access.
- Stop if you encounter another person's data and report the issue immediately.
- Do not modify, download, retain, or delete data that is not yours.
- Do not use denial-of-service, spam, phishing, or social-engineering techniques.
- Do not run broad automated scanners without written permission.
- Give us a reasonable opportunity to investigate before public disclosure.
- Encrypt any sensitive artifacts you send to us; we will provide a secure-upload link on request.
5. Scope
This policy covers websites and services owned and operated by empowered.guru, LLC, including our chatbot, blog, marketing site, and the managed infrastructure of client engagements where the issue is in our code or configuration. Third-party services, customer systems we do not control, and products merely linked from this website are out of scope unless empowered.guru directly controls the affected component.
6. What to expect
We aim to acknowledge useful reports within 3 business days, validate the issue within 10 business days, and keep the reporter informed when practical. Resolution timing depends on severity, complexity, and dependencies. We support coordinated disclosure after a fix or mitigation is available, and we credit researchers on our security acknowledgements page (where they request it).
7. Good-faith safe harbor
We will not pursue legal action against researchers for accidental, good-faith violations of this policy when they avoid harm, respect privacy, and cooperate with our investigation. We will work with researchers who act in good faith on any incidental policy or terms-of-service questions that arise from their research. This statement does not authorize testing of third-party systems or activity that violates applicable law.
8. AI-specific vulnerabilities
Prompt injection, jailbreaks, model exfiltration, training-data extraction, and other AI-specific vulnerabilities on systems we operate are within scope. We commit to coordinate on disclosure timelines that work for the broader AI-safety community and to publish postmortems for material issues, redacting reporter identities on request.
9. More about our approach
Read the broader Security page, our Incident Response procedure, or email security@empowered.guru with a policy question.

