Report a Security Issue — Allooloo

record as of 2026-09-12 · version 0.1 · allooloo.io

Report a Security Issue

1.1
Report through the contact form at allooloo.io/#contact (the only support door). Machine-readable: /.well-known/security.txt on every zone.
1.2
Scope: allooloo.io, *-cm-kg.ai (surfaces, mcp. and agent. hosts), agentic-*.ai, capitalmarketsknowledgegraph.ai, cm-record.org and the Azure origins behind the doors.
1.3
What to send: the host, the path, the request that shows the issue, the date and time (UTC), and how to reach you.
1.4
What happens: the report is read within one business day; a fix is confirmed to the reporter; the surface version carries the date.
1.5
Headers as content: strict Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, Referrer-Policy, X-Frame-Options, Permissions-Policy on every response; no inline scripts anywhere.
1.6
Preferred languages: English.