Security and trust
Report a vulnerability
How to tell Mojo Up about a security problem in AI Workbench, its nodes, the mobile app, Mojo Up AI Cloud or AIOE.
If you think you have found a security problem in anything Mojo Up makes, please tell us privately first, so we can fix it before others can use it.
How to report
Email security@mojoup.com.au with:
- what is affected: AI Workbench, a node (
mojoup-node), the mobile app, Mojo Up AI Cloud or self-hosted AIOE, and its version if you know it (on a node,mojoup-node version; on AIOE, theversionthat/healthzreturns); - what the problem is, and what someone could do with it;
- the steps to reproduce it, as short as you can make them;
- how we can reach you, and whether you would like to be credited.
Please do not include real personal data or other customers' data. If you need to show us something sensitive, say so and we will arrange a safer way to share it.
What we ask of you
- Give us a reasonable time to fix the problem before you tell anyone else.
- Test only against your own account, your own organisation and your own machines. Do not access, change or delete other people's data, and stop as soon as you have shown the problem.
- Do not degrade the service for others: no denial-of-service testing, spam or social engineering of Mojo Up staff or customers.
What you can expect from us
- We will acknowledge your report and keep you told of our progress.
- We will let you know when it is fixed. AI Workbench releases that fix a security problem are marked as security releases in the release notes.
- We will credit you if you would like us to.
Not security problems
For bugs that are not security problems, and for questions, see Support.