> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sawmills.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Vulnerability Disclosure

> How to report security vulnerabilities affecting Sawmills and Mills.

## Report a security issue

If you discover a suspected vulnerability or security incident affecting Sawmills or Mills (Agentmills), email [security@sawmills.ai](mailto:security@sawmills.ai).

This reporting process covers our products, services, infrastructure, and the Sawmills Slack app, including its Mills agent, integrations, and handling of Slack data.

## What to include

To help us investigate, please include:

* A description of the issue and where you found it.
* Steps to reproduce it and its potential impact.
* The date and time you observed it.
* Relevant URLs and redacted screenshots or logs.
* Contact information for follow-up, if you wish.

Do not include passwords, API keys, access tokens, or other people's personal or confidential data in your initial report. We can coordinate an appropriate way to share additional evidence if needed.

## What to expect

Our security team will review your report, assess the issue, and provide updates as the investigation progresses.

Please coordinate disclosure with us and allow a reasonable opportunity to investigate and resolve the issue before sharing details publicly.

## Responsible research

Limit investigation to the minimum necessary to demonstrate the issue. Avoid accessing or modifying other customers' data, disrupting services, or attempting social engineering. If you encounter sensitive data, stop and report what you observed without collecting further data.

## Bug bounty

We do not currently offer a bug bounty program or monetary rewards. Security reports are welcome at [security@sawmills.ai](mailto:security@sawmills.ai).
