The controls we actually operate, what we deliberately do not claim, and how to report a vulnerability safely without breaching the Acceptable Use Policy.
Last updated: 14 August 2026 // Version 1.0 // Governing law: the laws of England and Wales
We would rather be accurate than impressive, so to be explicit:
If you believe you have found a security vulnerability, email security@seamix.ai with a description, the steps to reproduce, and the impact you believe it has. We aim to acknowledge within 3 working days and to keep you updated until the issue is closed.
We will not pursue or support legal action against you for good faith security research that follows the rules below, and we will treat such research as authorised under the Acceptable Use Policy.
We do not currently pay bounties. We are happy to credit reporters publicly with their permission.
If a security incident affects personal data and is likely to result in a risk to individuals, we will notify the Information Commissioner's Office within 72 hours of becoming aware, notify affected users without undue delay where the risk is high, and notify controller customers within 48 hours under the Data Processing Addendum. We will describe what happened, what data was involved, what we have done and what you should do.