AI Incident Reporting

Tell us when an output misleads or a control does not hold.

Version 1.0 · Effective Sep 23, 2026

Something went wrong. What now?

Report it through our contact page with the product, the time and the operation id or finding reference. Meanwhile you keep your controls: hold delivery of replies, or revoke an agent's key.

Where to report. An AI incident goes to the contact page. A vulnerability goes to Responsible Disclosure. A wrong finding whose evidence is correct goes to the contact page. Then: report, confirm, investigate, report back.

What counts as an AI incident

An output or a control failure in Cyberdroid AI Detection or Cyberdroid AI Investigation that misled a decision, or could have. Following the OECD, an incident is harm that happened and a hazard is harm that could plausibly happen. Report both. Examples:

  • A finding whose evidence does not support its score, or telemetry reported healthy when it was not.
  • A case that claims more than its evidence references support, or treats a dead feed as proof that nothing happened.
  • A request that reached an agent without an administrator's approval.
  • A reply delivered to a recipient your policy did not clear.
  • A translated request that changed an identifier or its meaning.
  • A detector alerting in production without a recorded promotion.
  • Any sign that text inside a log, alert or email changed what the system did.

What to include

  • The product and version.
  • The date and time, with time zone.
  • The operation id and reason, or the finding or case reference.
  • What happened, and what you expected.
  • Evidence, redacted as your policy requires, and what you have done so far.

What you can do now

  • Hold delivery. Approval and delivery are separate authorities, so you can stop replies without relying on the model.
  • Revoke a key. Each agent has its own key, and revoking it stops that agent.
  • Keep the record. Requests, refusals, promotions and rollbacks are already recorded. Avoid changes that would affect the evidence before you report.

Related

Responsible Disclosure

Usage Policy

Prompt Injection

Responsible Deployment

Agent Permissions

Contact
ARRTECH

© 2026 ARRTECH Corporation. All rights reserved.