Last updated: August 10, 2026
Security and AI Incident Reporting
Report suspected security, privacy, or AI safety problems promptly. Do not include unnecessary sensitive information in the first message.
What to report
- Suspected data exposure or unauthorized disclosure.
- Account compromise, phishing, or credential theft.
- A security vulnerability affecting the website or API.
- Unsafe, discriminatory, deceptive, or harmful AI output connected with a Lab activity.
- Unauthorized publication of participant work or media.
- Loss of a device or file containing Lab information.
How to report
Email contact@sozorockfoundation.org with the subject “Urgent AI Lab Security or AI Incident.” Include the affected page or system, date and time, what you observed, steps to reproduce if safe, and a contact method.
Safe reporting
Do not access information beyond what is necessary to confirm a problem. Do not modify, delete, download, publicly disclose, or retain other people’s information. Stop testing if it may disrupt service or affect users.
Response
We aim to acknowledge credible reports within three business days, preserve evidence, contain risk, assess legal obligations, notify affected parties where required, remediate the issue, and document lessons and controls.
Emergency
This channel is not an emergency service. Contact emergency services or the appropriate authority if there is an immediate threat to life or safety.