RESPONSIBLE DISCLOSURE

Security at BRAWLER AI

We welcome good-faith reports that help us protect BRAWLER athletes and their training data. Please report suspected vulnerabilities privately so we can investigate them.

Report a vulnerability

Email a concise report to:

security@brawlerai.com

Do not include passwords, access tokens, or unnecessary personal data in your report.

Helpful report details

  • The affected URL, feature, or MCP tool.
  • A clear description of the issue and potential impact.
  • Minimal steps needed to reproduce it safely.
  • Redacted screenshots, request details, or proof of concept.
  • A safe way to contact you with follow-up questions.

In scope

  • The BRAWLER web and mobile applications.
  • brawlerai.com and BRAWLER-controlled subdomains.
  • The BRAWLER MCP Integration and its OAuth flow.
  • Unauthorized access to BRAWLER account or training data.

Good-faith testing guidelines

  • Use accounts and data you own or have explicit permission to test.
  • Stop testing and report promptly if you encounter another person's data.
  • Do not exfiltrate data, degrade availability, send spam, or use social engineering.
  • Give us a reasonable opportunity to investigate before publishing details.

This policy provides a reporting channel. It does not grant permission to access, modify, or disrupt systems or data you do not own, and it does not create a bug-bounty or payment commitment.

For account, billing, or product questions, visit BRAWLER Support.