# Security Policy for madusankapremaratne.com ## Contact - Report a Security Issue Please report security vulnerabilities via the contact form on our website: https://madusankapremaratne.com/contact Include as much detail as possible, including: - Steps to reproduce the issue - Expected vs. actual behavior - Any relevant logs, screenshots, or proof-of-concept code - The specific LLM system or component affected ## Preferred Communication Please use the contact form linked above as the first point of contact for any report. If a more secure channel is required for a specific disclosure, request one through the contact form and it will be arranged directly. ## Response Timeline - **Initial acknowledgment**: Within 24 hours - **Initial assessment**: Within 3 business days - **Status updates**: Weekly until resolution - **Public disclosure**: Coordinated after fix is deployed (typically 30-90 days) ## Scope This policy applies to: - madusankapremaratne.com and all subdomains - LLM systems and AI services developed under the Knivok brand - APIs, web applications, and research prototypes - Third-party integrations where we are the data controller ## Out of Scope - Denial-of-service (DoS/DDoS) attacks - Social engineering or phishing attempts - Issues arising from misuse of public APIs (rate limiting, etc.) - Vulnerabilities in third-party services not under our control ## Safe Harbor We welcome good-faith security research and will not pursue legal action against individuals who: - Make a good faith effort to avoid privacy violations and data destruction - Interact only with systems explicitly listed in scope - Provide reasonable time to remediate before public disclosure - Do not violate any applicable laws or regulations ## Acknowledgments We thank security researchers who help us improve the security and safety of our LLM systems. Public acknowledgments will be made upon request following responsible disclosure. ## Policy Updates This policy may be updated periodically. Last updated: 2026-09-02