SABLE / Security

Security and disclosure.

How SABLE protects data and how to report a problem, with server-side enforcement, organization scoping, and encryption in transit and at rest.

Last updated August 18, 2026

01Reporting

Report a vulnerability.

  • Good-faith security reports are welcome at security@sablealpha.com, a monitored mailbox.
  • Please include reproduction steps and avoid privacy violations, data destruction, or service degradation.
02Scope

Scope and safe harbor.

  • SABLE does not currently publish a safe-harbor statement, so testing against production systems is not authorized without written permission.
  • SABLE runs no paid bug bounty and makes no promise of payment.
03Posture

Current posture.

  • Access to customer data is enforced server-side and scoped to the organization, and no client is authoritative for identity or access.
  • Data is encrypted in transit and at rest, and operational logs carry metadata only, never passwords, tokens, prompts, or content.
  • This page makes no claim of certification or complete security.
04Contact

Questions about this document go to hello@sablealpha.com, and the other policies are linked in the footer.