Security

TermAI is an SSH client — security is the product. If you believe you've found a vulnerability, we want to hear from you.

Reporting a vulnerability

Email [email protected] (or [email protected]) with a description of the issue, steps to reproduce, and the affected version/platform. Please give us a reasonable window to fix it before any public disclosure. We aim to acknowledge reports within 3 business days.

We don't run a paid bounty program yet, but we credit reporters (with your permission) once a fix ships.

How TermAI protects you

Scope

In scope: the TermAI iOS and Android apps and the termai.sh backend. Out of scope: issues in third-party SSH servers you connect to, social engineering, and reports that require a rooted/jailbroken device or physical access to an unlocked phone.

Related: Privacy policy · Terms · About