Galileo AI: The AI Observability and Evaluation Platform

Galileo

Responsible Disclosure Program

Last updated at: Mar 4, 2026

Our Commitment to Security

We are committed to maintaining the highest standards of security across our platform. We welcome the support of the security research community and encourage responsible disclosure of vulnerabilities that help us protect our users, partners, and infrastructure.

This program does not offer monetary rewards or service credits. Instead, we provide:

1. Scope of Testing

Testing is permitted only on systems we own and operate.

In Scope

Out of Scope

2. Rules of Engagement

To ensure safe and responsible testing:

Researchers acting in good faith and following this policy are protected under our Safe Harbor commitment.

3. How to Report a Vulnerability

A valid report should include:

If you believe you’ve discovered a security vulnerability, please contact our security team at: security@galileo.ai

We encourage encrypted communication where possible.

We acknowledge reports within 48 hours and provide updates throughout the triage process.

4. Triage & Validation Process

Our security and engineering teams follows a structured workflow:

5. Severity Matrix

Severity reflects impact, not attacker identity.

Severity Definition
Critical Full system compromise, admin takeover, RCE, authentication bypass
High Sensitive data exposure, major privilege escalation, critical workflow abuse
Medium Limited data exposure, moderate privilege escalation, workflow manipulation
Low Minor misconfigurations, low‑impact issues
Informational Non‑exploitable best‑practice issues

6. Safe Harbor

We will not pursue legal action against researchers who:

7. Responsible Disclosure Framework

Submission Requirements

Remediation SLAs

Disclosure Timeline

8. Researcher Recognition

We value the contributions of the security community. Researchers who responsibly disclose vulnerabilities may be:

9. FAQs

Do you offer monetary rewards / bug bounties?

No. This is a no‑reward Responsible Disclosure Program. For recognition, please refer to the Researcher Recognition section.

Can I disclose the vulnerability publicly?

Only after we confirm the fix.

What if I accidentally access sensitive data?

Stop immediately and report it. Acting in good faith protects you.

Do insider‑only vulnerabilities count?

Yes — severity is based on impact, not attacker identity

10. Contact Us

If you believe you’ve discovered a security vulnerability, please contact our security team at: security@galileo.ai

We encourage encrypted communication where possible.