Security
Security
Last updated: June 17, 2026
Security reports help protect people using Negen. If you find a vulnerability, please tell us before sharing it publicly.
Report a vulnerability
Email security@negen.ai with a clear description, steps to reproduce, affected URLs or versions, and the impact you believe the issue has.
For sensitive reports, ask for an encryption key before sending secrets, proofs, or private data.
Rules of engagement
- Do not access, change, delete, or disclose other users' data.
- Do not run destructive tests, spam, denial-of-service tests, social engineering, physical attacks, or automated scans that degrade the service.
- Use your own account and test data where possible.
- Give us reasonable time to investigate before public disclosure.
Bounties
Negen does not have a standing bounty program yet. We may choose to reward high-impact reports later, but no payment is promised unless a written bounty program says so.
Good-faith research
If you follow these rules and report in good faith, we will not treat your research as an attack on the service. This does not protect activity that harms users, accesses private data, or breaks the law.