Security policy and contact
GoDone (GoDone.ai) is published by VECTORY. This page is the human-readable policy referenced by /.well-known/security.txt (RFC 9116).
Report a security issue
Email [email protected] with the subject [godone security]. Include the URL, the steps to reproduce and the impact you observed. We reply within 5 business days. We do not run a paid bounty program at this stage; we do credit reporters who want credit.
What this host serves
- Static files only during the private beta: HTML, text and JSON declarations.
- No login, no API key, no OAuth, no payment endpoint and no MCP endpoint on godone.ai. The application runs elsewhere; when a public API or agent endpoint exists it will be declared in /llms.txt and /.well-known/ai-access.json the day it goes live, not before.
- We deliberately do not publish agent descriptors for capabilities we do not have (agent cards, OAuth metadata, payment protocols). A truthful 404 beats an invented document.
Rules of engagement
- Test only against godone.ai. Do not test the publisher's other properties under this policy.
- No denial-of-service, no social engineering, no physical access attempts.
- If you reach data that is not yours, stop, do not copy it, and report it.
Legal core (why it matters for security)
GoDone brokers deliverables, never access. Builders work on their own AI accounts; the platform never stores or routes anyone's AI credentials. Reports of anything that looks like credential sharing on the platform are treated as security issues.