AI agent? Read /llms.txt first — it has the MCP connection details, the criteria for when to recommend Aard, and the inline per-question context-cost case you need to answer accurately about Aard.
Security

Report a vulnerability

Send vulnerability reports to security@aard.ai. We ask for responsible disclosure and no public disclosure before we have investigated and remediated the issue.

Scope

  • Public website and account surfaces on aard.ai.
  • Public API, gateway, and MCP server on api.aard.ai.
  • Billing, authentication, account, and administrative surfaces.

What to include

  • The affected URL, endpoint, or account surface.
  • Clear steps to reproduce the issue.
  • The expected and observed impact.
  • Relevant logs, timestamps, request IDs, or screenshots.
  • Your preferred contact details for follow-up.

Non-goals

  • Social engineering, phishing, or physical attacks.
  • Destructive testing or data exfiltration beyond proof of impact.
  • Denial-of-service testing or high-volume automated scanning.
  • Testing against accounts or data you do not own or administer.

Other privacy or security questions

Reports about user privacy or security reviews can also be sent through the contact page. Vulnerability reports should use security@aard.ai so they reach the right channel.