Security & responsible disclosure
AIowa LLC values coordinated, good-faith security research and treats vulnerability reports with priority and discretion.
1. Scope
This policy covers the public web properties operated by AIowa LLC, including this site (https://aiowa.dev). Each property may publish its own security and disclosure guidance where appropriate.
2. How to report
Please report suspected vulnerabilities privately to hello@aiowa.dev. Include a clear description, the affected URL or surface, reproduction steps, and your contact details.
Include “Security Report” in the subject line so the report is routed promptly. Do not include sensitive personal data beyond what is needed to reproduce the issue.
3. Coordination expectations
We ask researchers to avoid destructive or disruptive testing against live services, to refrain from accessing or exfiltrating data beyond what is necessary to demonstrate an issue, and to allow a reasonable disclosure window after reporting.
We will acknowledge reports, investigate in good faith, and keep reporters informed of remediation status.
4. Out of scope & status
Social engineering, physical attacks, spam, and denial-of-service testing are out of scope. AIowa LLC does not currently claim SOC 2, ISO certification, or third-party penetration-test status; this policy is a statement of reporting practice, not a certification claim.