How to report a security issue to Vypr
Last Updated: August 2026
VyPr AI AB operates vyprsec.ai. If you have found a security issue on one of our sites, we would like to hear from you. This page explains what we accept, how to report it, and what protections apply to researchers who follow the rules.
We do not operate a paid bug bounty program. Unsolicited reports will not be compensated with financial rewards or swag.
Send reports to [email protected] and include:
You will receive an automated reply confirming receipt. The reply also states that we do not pay for reports. A person will get back to you within five business days.
In scope: web applications and services we operate under vyprsec.ai and its subdomains, for example docs.vyprsec.ai and cve.vyprsec.ai.
Not in scope: services operated for us by third parties, such as Substack or Cloudflare Pages. Report issues in those platforms to the provider.
We will not accept reports for:
A report must show the issue in working form. We need reproducible steps that demonstrate an actual exploit, not just an indication that a weakness might exist. Raw output from automated scanners such as Nessus, Acunetix, Burp Scanner, Qualys or nuclei is not a report. We close those submissions without further review.
If you make a good faith effort to follow this policy, we will consider your research to be authorized, we will not pursue legal action against you, and we will work with you to understand and resolve the issue.
This protection does not apply if you:
If you encounter personal data during your research, stop testing immediately, notify us at [email protected], and permanently delete any copies you have made. Retaining or disclosing this data violates this policy and revokes your safe harbor protection.
We will review your report against this policy and reply. If it contains a valid, reproducible PoC for an issue we consider in scope, we will work on a fix and may ask follow up questions. We do not pay bounties or give rewards, and requests for payment will close the report.
Please give us reasonable time to fix an issue before disclosing it publicly, and do not publish details without our written approval.
This policy is governed by the laws of Sweden. Disputes arising in connection with it are subject to the exclusive jurisdiction of the courts of Sweden.