SABLE / Security
Security and disclosure.
How SABLE protects data and how to report a problem, with server-side enforcement, organization scoping, and encryption in transit and at rest.
Last updated August 18, 2026
01Reporting
Report a vulnerability.
- Good-faith security reports are welcome at security@sablealpha.com, a monitored mailbox.
- Please include reproduction steps and avoid privacy violations, data destruction, or service degradation.
02Scope
Scope and safe harbor.
- SABLE does not currently publish a safe-harbor statement, so testing against production systems is not authorized without written permission.
- SABLE runs no paid bug bounty and makes no promise of payment.
03Posture
Current posture.
- Access to customer data is enforced server-side and scoped to the organization, and no client is authoritative for identity or access.
- Data is encrypted in transit and at rest, and operational logs carry metadata only, never passwords, tokens, prompts, or content.
- This page makes no claim of certification or complete security.
04Contact
Questions about this document go to hello@sablealpha.com, and the other policies are linked in the footer.
