API documentation

Security disclosure

How to report a vulnerability in Stonewake, and what happens next, on one page. This is our coordinated vulnerability disclosure policy; the security.txt file described below points to it.

Scope

  • In scope: stonewake.ai (company site), app.stonewake.ai (dashboard), api.stonewake.ai (API), docs.stonewake.ai (this documentation) and mcp.stonewake.ai (MCP endpoint).
  • Out of scope: other customers' workspaces and data, denial of service, social engineering, physical attacks, and third-party services we do not operate.

How to report

  • Write to contact@stonewake.ai with "Security" in the subject, in English or German.
  • Include what is needed to reproduce: host and path, the request, and the observed effect. Never include live keys, credentials or workspace data in a report.

What to expect

  • Acknowledgement within three business days, then a first assessment with an indicative fix path.
  • We keep you informed until the issue is resolved.
  • No bug bounty: we do not pay for reports.

Safe harbour

  • Good-faith research within the scope above is authorised when it stops at demonstrating an issue, does not access, modify or delete data that is not your own, and does not degrade the service. We will not initiate legal action against researchers who follow this policy, and we ask for a reasonable time to fix before public disclosure.
  • Testing against other customers' data, denial of service, and any use of found data beyond what a report needs are outside the safe harbour. This authorisation covers our own services; it cannot bind third parties whose infrastructure delivers them.

security.txt

The company site publishes the canonical /.well-known/security.txt (RFC 9116) with the contact address, a link to this policy and an expiry date; the dashboard and this documentation carry copies that point to it.

Related: Security overview, API security.