Security & Disclosure
Last updated: September 1, 2026
At Praesidium, security is central to our product and operations. This page describes our approach to security and how to report vulnerabilities responsibly.
1. Security approach
Our environments are designed to resist manipulation: verifiers run outside the container, grading is state-based, and each episode is reset from a clean, deterministic image. Our infrastructure follows the principle of least privilege, uses strong access controls, and is subject to regular review.
2. Responsible disclosure
We welcome reports of security vulnerabilities affecting our website or services. If you believe you have discovered a security issue, please email us at security@praesidiumsystems.ai with the following information:
- A clear description of the vulnerability and its potential impact.
- Steps to reproduce the issue, including any proof-of-concept code or screenshots.
- Your contact information and, if applicable, an expected disclosure timeline.
3. Disclosure guidelines
- Do not access, modify, delete, or exfiltrate data beyond what is necessary to demonstrate the issue.
- Do not disrupt the availability of the site or services.
- Do not share details of the vulnerability publicly until we have had a reasonable time to address it.
- Comply with all applicable laws.
4. Our commitment
We will acknowledge receipt of your report within 5 business days and will work to validate, triage, and remediate reported issues. We are happy to credit responsible researchers in our disclosure notes, with their permission.
5. Data and synthetic environments
Our RL environments contain only synthetic, generated data. No real patient, client, or customer records are used. This reduces the risk of exposing sensitive personal information through our benchmark and research infrastructure.
6. Contact
For security questions or to report an issue, email security@praesidiumsystems.ai.