← Back to Sidle
Responsible Disclosure Policy
Last updated: August 17, 2026 · Applies to Sidle by RAY AI
We take the security of Sidle and the data our users entrust to us
seriously. If you believe you have found a security vulnerability in
sidle.ai or the Sidle browser extension, we appreciate your help in
disclosing it to us responsibly.
How to report
- Email legal@sidle.ai with the subject line
[SECURITY].
- Include steps to reproduce, affected URLs or components, and the potential impact.
- If the report involves account data, use a test account where possible.
What we promise
- We acknowledge reports within 3 business days.
- We keep you informed about remediation progress and let you know when the issue is fixed.
- We will not take legal action against researchers who act in good faith within this policy.
Ground rules
- Do not access, modify, or delete data that is not your own.
- No denial-of-service testing, spam, social engineering, or physical attacks.
- Do not publicly disclose the issue before we have had a reasonable chance to fix it (coordinated disclosure, typically 90 days).
Scope
sidle.ai (web application and API)
- The Sidle browser extension
Third-party services we use (Stripe, Sentry, Resend, LinkedIn itself) are out of
scope — please report issues there to the respective vendor.
Machine-readable
See /.well-known/security.txt (RFC 9116).