"48.9% of organizations are entirely blind to AI agent behavior" — Salt Security, April 2026

ORILink — responsible disclosure

Security

If you believe you've found a security vulnerability in ORILink, we want to hear from you. This page describes how to report it and what to expect.

Reporting vulnerabilities

If you believe you've found a security vulnerability in ORILink, please report it to security@talonyx.ai. We review all reports and respond within 72 hours.

Please do not publicly disclose vulnerabilities before we've had the opportunity to investigate and address them.

What to include

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Your contact information (optional — anonymous reports accepted)

Scope

  • ORILink SDK (Individual and Business)
  • talonyx.ai and dev.talonyx.ai

Out of scope

  • Theoretical attacks without proof of concept
  • Social engineering
  • Physical attacks

Response

We will acknowledge receipt within 72 hours and provide an estimated resolution timeline. We do not currently offer a bug bounty program but we do recognize researchers who report valid vulnerabilities (with your permission).