Security
Version 1.0 — effective as of 21 July 2026
Samsa Labs AG operates AI media-generation services and the content-provenance infrastructure behind them. We welcome reports from security researchers, customers, and the public, and we treat them as a core part of keeping our platform and the provenance information we publish trustworthy.
1. Reporting contact
Send all security and provenance reports to security@samsa.ai.
This address is monitored during Swiss business hours. Please write in English or German. Do not report security issues through public channels such as social media, or through our general support address.
2. What to report
We would like to hear about:
- Security vulnerabilities in our web application, public API, or infrastructure — including authentication or authorisation flaws, data exposure, injection vulnerabilities, and issues that allow one customer to access another customer’s content.
- Content Credentials and provenance issues — anything that causes our C2PA Content Credentials to be missing, incorrect, misleading, or removable; problems with our imperceptible watermarks; or incorrect results from our detection service at detect.samsa.ai.
- Non-conformance of our C2PA Generator Product with the C2PA Content Credentials specification or the requirements of the C2PA Conformance Program.
Reports in the last two categories are handled under the same process as security vulnerabilities. Where a report concerns our conformance with the C2PA specification or Conformance Program requirements, we additionally notify the C2PA as required by our obligations under that programme.
3. Scope
In scope:
- samsa.ai and its subdomains, including app.samsa.ai, api.samsa.ai and detect.samsa.ai
- Our public API and MCP server
- The C2PA Content Credentials, watermarks, and visible AI labels applied to media generated through our services
Out of scope:
- Third-party services we use but do not operate (report those to the provider concerned)
- Findings from automated scanners without a demonstrated, exploitable impact
- Missing security headers, TLS configuration preferences, or similar best-practice observations with no demonstrated impact
- Social engineering of our staff or customers, physical attacks, and spam or denial-of-service testing
4. How to report
Please include:
- A description of the issue and its potential impact
- Precise steps to reproduce it, including affected URLs, request details, and the date and time of your testing (with time zone)
- Any proof-of-concept material, screenshots, or media files that demonstrate the issue
- How you would like to be credited, if you would like to be named
Please send the report from an address we can reply to, and keep the details confidential until we have had a reasonable opportunity to remediate the issue (see section 6).
5. Our response
| Stage | Our commitment |
|---|---|
| Acknowledgement | Within 3 business days of receipt |
| Initial assessment and severity classification | Within 10 business days |
| Remediation target — high severity | 30 days from confirmation |
| Remediation target — moderate severity | 90 days from confirmation |
| Remediation target — low severity | 180 days from confirmation |
We will keep you informed of our progress and let you know when the issue is resolved. Where a fix requires action by a third-party supplier, we will tell you and track it to closure.
6. Good-faith research
If you make a good-faith effort to comply with this policy while researching and reporting a vulnerability, we will regard your research as authorised, we will work with you to understand and resolve the issue quickly, and we will not pursue or support legal action against you in relation to that research.
Good faith means, in particular, that you:
- access only accounts and data that belong to you, or for which you have explicit permission
- do not access, modify, delete, or exfiltrate other people’s data — if you encounter personal data, stop immediately and tell us
- do not degrade, disrupt, or overload our services
- do not publicly disclose the issue before we have remediated it or before 90 days have passed since your report, whichever comes first, and coordinate the timing with us
We do not currently operate a paid bug-bounty programme, and reports are not eligible for monetary rewards. With your permission we are glad to credit you publicly once the issue is resolved.
7. Contact
Samsa Labs AG
Pilatusstrasse 18, 6003 Luzern, Switzerland
security@samsa.ai
For non-security enquiries, please see our Imprint.