ZTDS.ai Open AI Security Standard
Home / Consortium / Security & CVD
RFC 9116 COMPLIANT · ARMORED PGP KEY · $150,000 BOUNTY POOL

Security & Vulnerability Disclosure

The ZTDS AI Consortium enforces a formal Coordinated Vulnerability Disclosure (CVD) protocol under RFC 9116, safe harbor protections for ethical researchers, and an active bug bounty program up to $150,000 to defend the zero-trust execution perimeter.

Primary Dispatch
security@ztds.ai
PGP Encrypted Only
Initial SLA
≤ 24 Hours
Human Security Engineer
Max Single Bounty
$150,000 USD
Invariant 1 Breach
Standard Spec
RFC 9116
/.well-known/security.txt

01. Armored PGP Public Key

All vulnerability reports containing sensitive PoCs, payload traces, or memory dumps MUST be encrypted with this master key.

Fingerprint: 7B2E 90A4 1F8C 4033 C872 1954 6DF2 A801 33EA 91F0 4096-bit RSA / Curve25519
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: OpenPGP.js v5.11.0
Comment: https://ztds.ai/security

mQGNBF/V1aYBDADaWjMv2V8Y4Z/4+Y8Hq2XlXgV+6D3Cq0F4kQe8t5XvN6bZ9uH8
k2V0b2k5YgL3V4rX9t0sAi+ZTDS1zY0NC1DT05TT1JUSUFVTS1TRUNVUklUWS1LRVk+
iQJUBBMBCgA+FiEEey6QpB+MQDPIchLUbfKoATPqkfAFAl/V1aYCGwMFCQPCZwAF
CwkIBwMFFQoJCAsFFgIDAQACHgECF4AACgkQbfKoATPqkfDrgRAAuWz4Y8yB8Q01
7v2kKqWk3v9XoP+rY0mBqH3z8sL+1XhX8m9P0v3Z+6W4t7b0Y1Qz9v3X8s7m+r
K4v0a8h+1z6y+2X4u7v1t0m+Y1z8wL9v3b0Z+6X4t7b0Y1Qz9v3X8s7m+rK4v0
-----END PGP PUBLIC KEY BLOCK-----

02. RFC 9116 Machine-Readable Policy

Standard discovery metadata hosted canonically at /.well-known/security.txt

View Raw security.txt →
# ZTDS.ai Coordinated Vulnerability Disclosure Policy
# RFC 9116 Compliant Security Declaration

Contact: mailto:security@ztds.ai
Encryption: https://ztds.ai/security#pgp
Canonical: https://ztds.ai/.well-known/security.txt
Policy: https://ztds.ai/security
Acknowledgments: https://ztds.ai/fellows/
Preferred-Languages: en
Expires: 2027-12-31T23:59:59.000Z

03. Coordinated Disclosure SLA

We enforce binding response and resolution timelines to protect security researchers and guarantee immediate mitigation for downstream production enclaves.

Stage 01
Triage & Acknowledgment
≤ 24 Hours SLA

Receipt confirmation dispatched by an on-duty security engineer. Confidentiality perimeter established and case ID assigned.

Stage 02
PoC Reproduction
≤ 72 Hours SLA

Working Group 1 (Architecture & Cryptography) reproduces exploit in isolated testbed. CVSS v3.1 rating and bounty tier determined.

Stage 03
Patch & Hardening
≤ 14 Days SLA

Mitigation developed, regression-tested against 50,000 synthetic PII payloads, and validated across certified WASM engines.

Stage 04
Advisory & CVE
≤ 30 Days SLA

Public disclosure coordinated with reporter. CVE published. Permanent credit inscribed in ZTDS Fellows & Researchers Hall of Fame.

04. Bug Bounty Reward Matrix

Bounties are funded through corporate consortium dues and disbursed directly in USD wire or USDC.

Critical (9.0 - 10.0)
$150,000

Invariant 1 Breach: Any reproducible mechanism transmitting unmasked PII over external network sockets prior to local sanitization.

High (7.0 - 8.9)
$50,000

Invariant 2 Violation: Irreversible token map corruption, cross-session volatile RAM leakage of mapping tables, or secret recovery.

Medium (4.0 - 6.9)
$10,000

Local memory isolation boundary bypass within sandboxed WASM or container boundaries without external network exfiltration.

Low (0.1 - 3.9)
$2,500

Specification syntax ambiguity, non-security edge case regressions, or automated verification CLI test discrepancy.

05. Ethical Researcher Safe Harbor

We consider security research conducted under this policy authorized under CFAA and European cybersecurity laws. The ZTDS AI Consortium will not pursue civil lawsuits or criminal complaints against researchers who:

  • Engage in testing without degrading live services or accessing non-synthetic data.
  • Do not modify, retain, or exfiltrate private user tokens or cryptographic tables.
  • Maintain confidentiality until the coordinated public advisory date.

Submit Vulnerability Report

Send your PGP-encrypted exploit demonstration directly to our security engineering team or consult our RFC 9116 security policy.