Current security posture
AdaMind infrastructure is hosted through OVHcloud in Virginia, USA. Server access is restricted to authorized AdaMind development and maintenance. IIS request logging is disabled server-wide, but limited PHP application and GitHub integration logs may exist for errors and troubleshooting.
AdaMind infrastructure backups exclude customer projects and customer databases. Customers must maintain independent backups. AdaMind does not guarantee an encrypted customer secrets vault; customers control storage of project API keys and credentials and may delete or replace them.
Report securely
Email admin@adamind.dev with subject “Security Vulnerability.” Include the affected component, impact, reproducible steps, and minimal proof. Do not include unnecessary personal data or active secrets.
Good-faith research rules
- Test only accounts and data you own or have written permission to use.
- Stop when encountering another user’s data.
- Do not persist access, alter data, degrade service, or access production secrets.
- No denial of service, social engineering, phishing, high-volume scanning, credential stuffing, or extortion.
- Allow reasonable remediation time before disclosure.
Compliant good-faith research will not by itself trigger legal action by AdaMind, but this does not bind third parties or authorize unlawful activity. No bounty is promised.
Incident response
AdaMind will investigate confirmed incidents and notify affected users and authorities without unreasonable delay where required by applicable law, considering scope determination, restoration, and lawful law-enforcement requests. Customers remain responsible for project code, secrets, permissions, dependencies, deployed applications, and backups.
AdaMind