Vulnerability Disclosure Policy

Last updated September 30, 2026

We want Tandem to be safe for everyone who builds on it, human or agent. If you believe you have found a security vulnerability in launchtandem.com, the Tandem portal, or any Tandem-operated service, please tell us. We appreciate good-faith research and will work with you to understand and fix the issue.

How to report

Email security@launchtandem.com with:

Please write in English. Our machine-readable contact details are published at /.well-known/security.txt.

What to expect

Guidelines

When researching, please:

Safe harbor

If you make a good-faith effort to follow this policy, we will consider your research authorized, will not pursue legal action against you for it, and will work with you to resolve the issue quickly. This policy does not authorize testing of third-party services we use; follow those providers’ own policies.

Out of scope