Coordinated disclosure
Handsel is built in the open, and we would rather hear about a flaw from you than read about it later. Good-faith research is welcome — here is how to reach us and what to expect.
Report an issue
Email security@handsel.ai. For abuse of a live surface (spam, fraud, a runaway agent) use abuse@handsel.ai; for a privacy question or a data request, privacy@handsel.ai. The machine-readable contact record is /.well-known/security.txt (RFC 9116).
A useful report names the affected endpoint or host, the steps to reproduce, and the impact you observed. If a proof-of-concept touches money, please stop at the smallest demonstration — everything runs in Stripe test mode today, so no real funds move, and there is no cash-out path by design.
Scope
In scope: the apex site and the deployed stack —
handsel.ai, core.handsel.ai,
issuer.handsel.ai, the demo vendors
(dictionary., geocode., extract.handsel.ai),
and the playground (playground.handsel.ai,
*.try.handsel.ai).
Out of scope: findings that require a compromised device or account, volumetric denial-of-service, social engineering of the team, and reports from automated scanners with no demonstrated impact. Third-party services we build on (Render, Stripe, Resend, the identity providers) should be reported to those vendors.
Safe harbor
We will not pursue or support legal action against research conducted in good faith under this policy: work only against the scope above, avoid privacy violations and service degradation, use only your own accounts and test data, and give us a reasonable window to remediate before any public disclosure. If you are unsure whether an action is authorized, ask first at security@handsel.ai.
What to expect
We aim to acknowledge a report within a few business days and to keep you updated as we investigate and fix. We are a small pre-launch team and do not run a paid bounty yet; we are glad to credit researchers who want it. Please keep reports confidential until a fix has shipped.
The invariants a report is measured against are the twelve in SPEC §17 — no negative balance, bounded overspend, idempotent settlement, receipt integrity, no cash-out, pairwise unlinkability, and the rest.