Skip to content
Viorant
Product ▾
HubOptional local authoring workspace .vioPortable AI system definition
TrustSigning, provenance, and verification HelixTransformation and deployment engine
Viorant CloudManaged infrastructure for AI workloads SentinelObservability, compliance, and audit
Download the Hub
QUICK LINKS
OverviewExplore the platform → PricingPlans and options → Contact salesTalk to our team →
AI Deployment InfrastructureA neutral system definition. Optional services.
Vision Who Is It For ▾
WHO IS IT FOR
01AI platform teamsCreate a shared system record for AI work. 02Enterprise architectsDefine systems without locking in one stack. 03AI engineering teamsKeep a system definition alongside the work. 04Security & governanceReview stated AI-system evidence with context. 05Engineering leadershipMake ownership and handoffs clearer.
06Product & innovationCarry AI-system intent from prototype to review. 07DevOps & SRE teamsBring system definitions into deployment workflows. 08Regulated AI teamsCreate a reviewable system record. 09AI consultants & solution architectsHand over systems with their declared context. 10Developer tool buildersBuild around a neutral AI system format.
Company ▾
COMPANY
AboutWho we are and what we are building Blog / Field notesInsights and updates from our work CareerJoin the team and help shape the future
PartnersCollaborating to build what's next InvestorsBackers supporting our mission ContactGet in touch with our team
Civilize intelligence.Built for teams shipping AI.
Download the Hub
Home/Security and vulnerability disclosure.

Security and vulnerability disclosure.

This page explains how to report a Viorant vulnerability privately, which systems are in scope, the safe-harbor terms for good-faith research, and the current security boundaries of Viorant products and releases.

Last updated: August 2026
01

Reporting a Vulnerability

Email security@viorant.ai. Please report privately and give us a chance to fix the issue before it is disclosed publicly.

We acknowledge every report within three business days and will tell you whether we consider it in scope, what we intend to do, and roughly when. If a report is not in scope we will say so plainly rather than leave it unanswered.

Viorant does not currently run a paid bug bounty. We credit researchers who ask to be credited.

02

What to Include

A useful report lets us reproduce the issue without guesswork:

  • The affected surface: the website, the Control Plane API, or the Viorant Hub desktop application, including its version.
  • Steps to reproduce, with the requests, payloads, or files involved.
  • What an attacker gains: the concrete impact, not only the class of bug.
  • Any proof-of-concept code, kept to the minimum needed to demonstrate the issue.
03

In Scope

  • viorant.ai and its subdomains.
  • The Viorant Control Plane API.
  • The Viorant Hub desktop application for macOS and Windows.
  • Release and update integrity, including signing, notarization, and the auto-update path.
04

Out of Scope

The following are not eligible, either because they are outside our control or because they do not describe a real attack:

  • Denial of service, volumetric testing, or automated scanning that degrades service for others.
  • Social engineering of Viorant staff, customers, or vendors, and physical attacks.
  • Vulnerabilities in third-party services we consume, which should be reported to those vendors.
  • Missing hardening headers, weak ciphers, or scanner output with no demonstrated impact.
  • Findings that require a compromised operating system, a rooted device, or an attacker who already has local access to the user account.
05

Safe Harbor

If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research.

Good faith means you avoid privacy violations, data destruction, and service degradation; you access only accounts and data you own or have permission to test; you stop as soon as you have demonstrated the issue; and you do not use the finding for any purpose beyond the report.

If a third party brings action against you for research conducted under this policy, we will make it known that your work was authorized.

06

Coordinated Disclosure

We ask for 90 days from acknowledgment before public disclosure, and we will usually be finished well before that. If a fix will take longer we will tell you why and agree a date with you rather than let the deadline pass in silence.

When a fix ships we will confirm it to you and, where the issue affected users, describe it in the release notes.

07

Where Your Data Can Travel

Some security properties are decisions about structure rather than controls added afterward. Three shape most of the answer:

  • Provider API keys are stored in your operating system keychain, scoped per user, and are never proxied through Viorant.
  • Viorant is not on your model execution path. The Hub builds and prepares artifacts; your application calls your model provider directly.
  • Authoring and testing run on your machine. The Hub works offline, and cloud connectivity is enrichment rather than a dependency.

How we handle the information we do collect is described in the Privacy Policy.

08

Release Integrity

macOS builds are signed with an Apple Developer ID certificate and notarized by Apple. Windows builds are code-signed. Published releases carry checksums, and the auto-update path verifies what it stages before installing it.

If you obtained Viorant Hub anywhere other than viorant.ai or dl.viorant.ai, we cannot vouch for it.

09

Supply Chain

Dependency scanning and secret scanning run in continuous integration across our repositories, and a failing scan blocks a release build rather than warning beside it.

Dependencies are pinned to immutable release tags so that a build cannot silently change underneath a published version.

On this page

  1. 01Reporting a Vulnerability
  2. 02What to Include
  3. 03In Scope
  4. 04Out of Scope
  5. 05Safe Harbor
  6. 06Coordinated Disclosure
  7. 07Where Your Data Can Travel
  8. 08Release Integrity
  9. 09Supply Chain

Found something?

Report it privately and we will work it with you.

security@viorant.ai ->

We acknowledge every report within three business days.

Build better.Ship with confidence.Download Hub today.

Download the Hub
macOSWindowsLinux
Viorant

Viorant builds AI Deployment Infrastructure.

Product
Hub .Vio Helix Trust Pricing
Company
About Vision Investors Careers Contact
Resources
Documentation Blog
Legal
Privacy Terms Security Cookies
© 2026 Viorant Inc. All rights reserved. Antler · NVIDIA Inception · Microsoft for Startups