PDL Logo
PDL Legal& Compliance Center
← Back to Directory
ACTIVE POLICY

Security Disclosure Policy

Security Disclosure Policy

Effective Date: June 3, 2026

At PsyData Labs L.L.C. (PDL), the security of our behavioral analytics, psychological signal processing systems, and artificial intelligence models is paramount. We value the critical role the independent security research community plays in helping us maintain an exceptional security posture aligned with SOC 2, ISO 27001/27701, NIST, GDPR, CPRA, and the NY SHIELD Act. This Security Disclosure Policy outlines our expectations, reporting procedures, and Safe Harbor provisions for vulnerability discovery and disclosure.

1. Safe Harbor Guidelines

To encourage responsible security research, PsyData Labs L.L.C. offers a Safe Harbor for researchers who act in good faith to discover and report vulnerabilities. If you conduct your research in accordance with this policy, PDL considers your actions authorized and will not initiate legal action or law enforcement investigations against you.

  • Good Faith: You must make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our services (including Denial of Service).
  • Compliance: You must comply with all applicable laws and regulations. However, if your security research strictly complies with this policy, PDL will not pursue civil action for accidental violations of our Terms of Service related to testing.
  • Data Protection: You must immediately halt testing and report your findings if you encounter sensitive data, including but not limited to Behavioral Data (D-BEH), Psychological Signals (D-PSY), Inference Outputs (D-INF), or any Restricted (S3+) or Highly Restricted (S4) data. Do not exfiltrate, save, or copy any user data.
  • Coordination: You must allow PDL a reasonable time frame to remediate the vulnerability before you disclose it publicly or to any third party.

2. Reporting Procedures

If you believe you have discovered a vulnerability, please report it immediately by emailing our security team.

  • Email Address: security@psydatalabs.com
  • Encryption: We highly encourage encrypting your communications using our public PGP key (available upon request or via our Trust Center).
  • Report Format: Your report should include:
    • A detailed description of the vulnerability and its potential impact.
    • The specific products, URLs, or APIs affected.
    • Step-by-step instructions or proof-of-concept (PoC) code to reproduce the issue.
    • Your IP address and the timestamp of when the testing occurred, to help us differentiate your research from malicious activity in our logs.

3. Scope of Testing

PsyData Labs L.L.C. expects researchers to restrict their testing to systems explicitly owned and operated by PDL.

In-Scope:

  • Public-facing web applications and APIs hosted on *.psydatalabs.com.
  • PDL behavioral telemetry endpoints and SDK integrations.

Out-of-Scope (Strictly Prohibited):

  • Volumetric attacks, including Denial of Service (DoS) and Distributed Denial of Service (DDoS).
  • Social engineering (e.g., phishing, vishing) directed at PsyData Labs L.L.C. employees, contractors, or clients.
  • Physical testing of PDL offices, data centers, or equipment.
  • Attempts to access, modify, or delete production data, including S2+ restricted data environments, AI training pipelines, or research enclaves.
  • Third-party vendor applications or services hosted by external providers (unless explicitly whitelisted).
  • Testing that disrupts the Human-in-the-Loop (HITL) processes or intentionally poisons our Synthetic Data pipelines.

4. Response and Remediation Commitment

PsyData Labs L.L.C. is committed to working collaboratively with security researchers. When you submit a vulnerability report in accordance with this policy, we will:

  • Acknowledge receipt of your report within three (3) business days.
  • Provide an estimated timeline for remediation based on the severity of the vulnerability, adhering to our internal vulnerability management SLAs.
  • Maintain an open dialogue regarding the status of the patch.
  • Notify you when the vulnerability has been successfully remediated.

5. Recognition and Reward

At our sole discretion, PsyData Labs L.L.C. may offer rewards or public recognition for exceptional vulnerability reports that lead to a material improvement in our security posture. Any rewards are contingent upon strict adherence to the Safe Harbor guidelines, including confidentiality prior to the authorized remediation.

Official Document Ledger Record

Security Disclosure Policy

ID: PDL-SEC-001•REV: 1.1.0
Classification LevelPublic-Facing
Policy OwnerPDL Office of the Executives
StatusACTIVE
Effective Date2026-07-30
Review CycleAnnual
Authorized Signatory
Kyyle Everett Garrow
Kyyle Everett GarrowChief Executive OfficerExecutive Leadership