RESPONSIBLE DISCLOSURE
Security at BRAWLER AI
We welcome good-faith reports that help us protect BRAWLER athletes and their training data. Please report suspected vulnerabilities privately so we can investigate them.
Report a vulnerability
Email a concise report to:
security@brawlerai.comDo not include passwords, access tokens, or unnecessary personal data in your report.
Helpful report details
- The affected URL, feature, or MCP tool.
- A clear description of the issue and potential impact.
- Minimal steps needed to reproduce it safely.
- Redacted screenshots, request details, or proof of concept.
- A safe way to contact you with follow-up questions.
In scope
- The BRAWLER web and mobile applications.
brawlerai.comand BRAWLER-controlled subdomains.- The BRAWLER MCP Integration and its OAuth flow.
- Unauthorized access to BRAWLER account or training data.
Good-faith testing guidelines
- Use accounts and data you own or have explicit permission to test.
- Stop testing and report promptly if you encounter another person's data.
- Do not exfiltrate data, degrade availability, send spam, or use social engineering.
- Give us a reasonable opportunity to investigate before publishing details.
This policy provides a reporting channel. It does not grant permission to access, modify, or disrupt systems or data you do not own, and it does not create a bug-bounty or payment commitment.
For account, billing, or product questions, visit BRAWLER Support.