Remarkable AI · Vulnerability Disclosure

Remarkable Ai Vulnerability Disclosure

Vulnerability disclosure

Remarkable AI runs a coordinated vulnerability disclosure program on Bugcrowd. A dedicated security contact is published.

CompanyApplicative SaasCustomer EngagementPersonalizationEcommerceArtificial IntelligenceCustomer SupportMarketing
Program: Bugcrowd

Disclosure Policy

Security Contact

Contact
emailsecurity@beremarkable.ai
Contact
postal115 Broadway, 5th Fl, New York, NY 10006
Contact
secondary_emailinfo@chatdesk.com
Contact
secondary_sourcehttps://www.chatdesk.com/responsible-disclosure-program
Contact
sourcehttps://www.beremarkable.ai/security

Source

Vulnerability Disclosure

remarkable-ai-vulnerability-disclosure.yml Raw ↑
generated: '2026-08-13'
method: searched
probe: true
source: https://www.chatdesk.com/responsible-disclosure-program
checked: '2026-08-13'

# NOTE: probe-security-programs.py rewrote this file on 2026-08-13 with a thinner,
# keyword-only body that dropped the contact, policy URL, statement and bug_bounty
# fields recorded on 2026-07-21. Per the pipeline's idempotency rule (never replace a
# stronger artifact with a weaker one) the earlier content is restored here and enriched
# with the formal Responsible Disclosure Program found on the legacy brand's site, which
# is materially richer than the security page: it carries scope, exclusions, a response
# timetable and safe-harbor language.
#
# BRAND NOTE (STEP 0c ownership justification for a different domain):
# https://www.beremarkable.ai/legal/terms states verbatim: "We (Chatdesk, Inc. DBA
# Remarkable AI) create software and solutions..." — Remarkable AI is the trading name of
# Chatdesk, Inc., which rebranded in 2024, so chatdesk.com is this company's own prior
# brand and not a third party.

provider: Chatdesk, Inc. DBA Remarkable AI

program:
  present: true
  name: Responsible Disclosure Program
  url: https://www.chatdesk.com/responsible-disclosure-program
  http_status: 200
  formal: true

contact:
  email: security@beremarkable.ai
  source: https://www.beremarkable.ai/security
  secondary_email: info@chatdesk.com
  secondary_source: https://www.chatdesk.com/responsible-disclosure-program
  postal: 115 Broadway, 5th Fl, New York, NY 10006

policy_url: https://www.beremarkable.ai/security
policy_url_legacy: https://www.chatdesk.com/responsible-disclosure-program

statement: >-
  Independent security researchers are encouraged to report security issues to
  security@beremarkable.ai. Applications are designed, developed, deployed and tested in
  accordance with leading industry standards (e.g., OWASP for web applications).

safe_harbor:
  present: true
  summary: >-
    The company commits not to pursue legal action against, or suspend the access of,
    researchers who discover and report a vulnerability in accordance with the Responsible
    Disclosure Program. It expressly reserves its legal rights where a researcher does not
    comply with the program terms.

response_commitment:
  acknowledgement: within 2 business days
  provides_timetable: true
  notifies_on_fix: true
  public_credit: with the researcher's permission

scope:
  in_scope:
  - Chatdesk / Remarkable AI services
  out_of_scope:
  - Unauthorized access to accounts
  - Modification or destruction of data
  - Denial-of-service testing
  - Malware distribution
  - Testing of third-party integrations
  - CSRF on anonymous forms
  - Banner / version disclosure
  - SSL/TLS configuration and security-header findings

bug_bounty: false
bug_bounty_note: >-
  No rewards, bounty table or third-party bounty platform. Note that the only security.txt
  reachable on any company host — https://help.beremarkable.ai/.well-known/security.txt —
  advertises a Bugcrowd program, but that document is INTERCOM's (it self-declares
  "Canonical: https://app.intercom.com/.well-known/security.txt" and points at
  bugcrowd.com/intercom). It belongs to the help-desk vendor, not to this company, and
  must not be read as a Remarkable AI bounty program. See
  well-known/remarkable-ai-well-known.yml.

security_txt:
  first_party: false
  note: >-
    No RFC 9116 security.txt is served on any first-party host. www.beremarkable.ai and
    www.chatdesk.com both return HTTP 404 for /.well-known/security.txt. The disclosure
    contact is published as HTML prose only, so an automated scanner will not find it.

certifications: []
certifications_note: >-
  No named certification (SOC 2 Type I or II, ISO 27001, PCI DSS, HIPAA, FedRAMP) is
  claimed on https://www.beremarkable.ai/security or on the legacy security page. The page
  references "3rd party security vulnerability assessments" during the testing phase but
  names no auditor, report or attestation. NO Compliance pointer is emitted.

trust_center:
  present: false
  note: >-
    No trust.beremarkable.ai, no Vanta/Drata/SafeBase portal, and no trust-center link on
    the security page. probe-security-programs.py returned trust=none.

evidence:
- source: https://www.beremarkable.ai/security
  status: 200
  kind: disclosure page
  keywords:
  - vulnerability
  - security research
  - security issue
  - security@beremarkable.ai
- source: https://www.chatdesk.com/responsible-disclosure-program
  status: 200
  kind: formal responsible-disclosure program
  keywords:
  - responsible disclosure
  - safe harbor
  - 2 business days
  - out of scope
- source: https://www.beremarkable.ai/.well-known/security.txt
  status: 404
  kind: negative probe
- source: https://www.chatdesk.com/.well-known/security.txt
  status: 404
  kind: negative probe