Security
Bounded experiments. Clear safeguards.
Stefanski AI treats security, privacy, and human oversight as core requirements for every experiment and integration.
Our approach
- Public information is separated from restricted experimental services.
- Private prototypes use access controls appropriate to their environment.
- Experiments are designed to minimize data collection and unnecessary retention.
- Credentials and secrets remain outside public source code.
- Systems are reviewed and updated as their capabilities and exposure change.
Experimental services
Services hosted on Stefanski AI subdomains may be restricted to authorized testers. The existence of a subdomain does not indicate that a service is generally available, suitable for production use, or approved for clinical workflows.
Do not submit protected health information, confidential business information, credentials, or other sensitive data to an experimental service unless its documentation explicitly authorizes that use.
Responsible disclosure
To report a suspected vulnerability, email contact@stefanski.ai with the affected URL, a clear description, steps to reproduce, and any relevant impact or evidence.
Please do not access data that is not yours, disrupt service availability, use social engineering, or conduct automated testing without written authorization. Stefanski AI does not currently operate a bug-bounty program.