Security Policy
Last updated: 3 September 2026
What this policy covers
AishiSec takes the security of its own website and services seriously. The same standard we ask of our clients. This policy explains how to report a security weakness you find in our website or systems.
How to report a security issue
Email your report to security@aishisec.com. The same address is published in our security.txt.
A useful report includes: what you found, where you found it (URL or service), the steps to reproduce it, and the potential impact. If you are reporting a weakness found while testing, please follow the guidelines below.
What we ask of testers
We welcome testing of our website, and we ask that you:
- Avoid anything that could disrupt service for other visitors.
- Do not access or alter data that is not your own.
- Do not attempt phishing or social engineering against AishiSec or its visitors.
- Share enough detail for us to reproduce the issue: a proof of concept is appreciated.
What you can expect from us
We treat security reports as a priority. We will acknowledge your report, work to confirm it, and keep you informed as we fix it. If you would like public credit for a confirmed weakness, tell us. We are glad to acknowledge good-faith work.
Good-faith testing
We review reports made in good faith and in line with this policy without pursuing action against the reporter, provided the testing stays within these guidelines and within the scope of the AishiSec website itself. Reports about systems belonging to our clients should be made to those clients. We cannot accept or act on them.

