Esan

Responsible disclosure

Last updated: September 6, 2026

Esan acts on your behalf: it signs into your apps, sends email, and can spend money within limits you set. A vulnerability here is not an abstraction, and we would rather hear about one from you than from a customer. If you have found something, this page tells you how to tell us and what happens next.

How to report

Email security@esan.ai. Include enough for us to reproduce it: the URL or endpoint, the steps, what you expected and what happened. A short screen recording is worth more than a long description. Write in English or Spanish, whichever you prefer.

Please report to us first and give us a chance to fix it before discussing it publicly. We will not ask you to stay quiet indefinitely — see the timelines below.

What we promise

There is no bug bounty. We are a small team and we would rather say so plainly than imply a reward we cannot pay. If that changes, it will be announced here first.

Ground rules

Research under this policy has to stay within these limits. They exist to protect other people's data, not to make your work harder.

Safe harbour

If you follow this policy in good faith, we will treat your research as authorised under the Spanish Criminal Code and the EU Directive on attacks against information systems, we will not pursue civil or criminal action against you, and we will not report you to law enforcement. If a third party brings action against you for research you conducted under this policy, we will make it known that your activity was authorised.

If you are unsure whether something is in scope, ask before you test. An email to security@esan.ai costs you a day and settles it.

In scope

Out of scope

These are either not vulnerabilities or not ours to fix, and reports about them will be closed without much ceremony:

Coordinated publication

We would like a fix to be live before a finding is public. Our default is 90 days from your report, or sooner if we fix it sooner — we will tell you when we ship. If we go quiet or the 90 days pass with no fix and no explanation, publish. A researcher should not have to keep a company's secret indefinitely because that company was slow.

If a vulnerability is being exploited in the wild, tell us immediately and we will work to a shorter timeline with you.

Responsible disclosure — Esan