Report a Security Issue
- 1.1
- Report through the contact form at allooloo.io/#contact (the only support door). Machine-readable:
/.well-known/security.txt on every zone. - 1.2
- Scope: allooloo.io,
*-cm-kg.ai (surfaces, mcp. and agent. hosts), agentic-*.ai, capitalmarketsknowledgegraph.ai, cm-record.org and the Azure origins behind the doors. - 1.3
- What to send: the host, the path, the request that shows the issue, the date and time (UTC), and how to reach you.
- 1.4
- What happens: the report is read within one business day; a fix is confirmed to the reporter; the surface version carries the date.
- 1.5
- Headers as content: strict Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options, Referrer-Policy, X-Frame-Options, Permissions-Policy on every response; no inline scripts anywhere.
- 1.6
- Preferred languages: English.