Last Updated: September 30, 2026
If you find a security problem in a website or service that IG Digital Lab runs, email [email protected]. A person reads that address. We run no paid bug bounty, but we triage every report and we credit you if you want.
IG Digital Lab is the trade name of IGGO, LLC, 3550 Watt Ave, Suite 408, Sacramento, CA 95821. This page covers systems that IGGO, LLC owns and operates. The machine-readable version is at /.well-known/security.txt (RFC 9116).
Write to [email protected] in English or Russian. Please include:
Do not send other people's personal data. A screenshot with the sensitive parts blacked out is enough. If you need an encrypted channel, say so in your first message and we will arrange one. We do not publish a PGP key today.
Please give us 90 days before you publish details. If 90 days pass with no fix and no agreed date, you may publish.
In scope: igdigi.com, firstreply.igdigi.com, ai.igdigi.com, the applications behind them, the AI receptionist that answers (916) 618-0502, and the code in our public repositories at github.com/igdigitallab. The phone line is our live business line. Prompt-injection findings are welcome by email. Please do not call in bulk or tie the line up while real callers may be trying to get through.
Out of scope:
If you make a good-faith effort to follow this policy, we consider your research authorized. We will not take or support legal action against you for it. If a third party takes legal action over the same research, we will say that your work followed this policy. Stop testing and report as soon as you reach personal data, and do not copy, change or delete anyone else's data.
This covers IGGO, LLC's own systems only. It does not bind anyone else, and it cannot authorize breaking a vendor's terms or the law.
We do not pay bounties. Once a fix ships, we credit you on this page by name or handle, if you want that.
Security reports: [email protected]. Anything else: [email protected].