Security Is a Design Constraint, Not a Page

We build AI targeting systems for the most hostile signal environment on earth. This page explains how we think about security, and how to reach us if you find something we missed.

Secure by Design

Our systems are engineered on the assumption that the environment is compromised. We assume jamming. We assume interception. We assume the link goes down at the worst possible moment. That assumption is not a compliance posture, it is a lesson carried home from the front line, and it shapes every architectural decision we make.

It is why FIXAIT runs inference entirely at the edge, with no cloud dependency and no requirement to emit. It is why our platforms navigate without GNSS and fight without a persistent datalink. A system that does not depend on a connection cannot be defeated through one. Attack surface is not something we audit at the end. It is something we refuse to build in at the start.

The same discipline applies to our organization. The identities of our people are protected. Technical data is compartmented and shared on a need-to-know basis. Sensitive work stays inside contracted government channels where it belongs. We are a Canadian sovereign company, and we treat the trust that comes with that as an operational responsibility, not a marketing line.

Coordinated Vulnerability Disclosure

If you believe you have found a vulnerability in our public-facing systems, we want to hear from you, and we will treat you like a professional. Report it privately to security@objexis.ai. Include a description of the issue, steps to reproduce it, your assessment of the impact, and the name or handle you want credited if you would like public acknowledgement.

In scope: objexis.ai, its subdomains, and the public web infrastructure we operate. If it is reachable from the open internet and belongs to us, it is fair game for good-faith research.
Out of scope: Deployed defence systems and fielded hardware. Attempting to access, acquire, track, or probe operational systems is not research, and it is not authorized. Also out of scope: denial of service, social engineering of our people or partners, physical intrusion, and third-party services we do not control.
Our commitment: Acknowledgement within 3 business days. A triage assessment within 10 business days. Straight answers about what we found and when it will be fixed. You will not be met with silence or a legal letter for doing the right thing.
Coordinated timeline: We ask for a standard 90-day window before public disclosure, and we will work with you on timing if a fix needs longer or lands sooner. Credit is yours if you want it, anonymity is yours if you prefer it.
Safe harbour: Research conducted in good faith under this policy is authorized. We will not pursue legal action against researchers who respect scope, access only the minimum data needed to demonstrate an issue, do not degrade service, and report promptly and privately.
No bounty, no pretence: We do not currently run a paid bounty program, and we will not pretend otherwise. What we offer is direct engagement with the engineers who built the thing, a fast fix, and public credit. When that changes, this page will say so.

A Note on Controlled Information

We are a defence technology company. Some things are not publicly testable, and some questions will not be answered on principle. Technical data on deployed systems, operational locations, partner details, and the identities of our people are protected as a condition of the work. Vulnerability reports touching any of these areas will be handled through the appropriate government and contractual channels, and we ask that they never be posted publicly.

If your research brushes against something you suspect is sensitive, stop and write to us. The correct disclosure path for this industry is a private report, not a public post. We respond fastest, and think most highly, of researchers who understand that.

A machine-readable version of this policy is published at /.well-known/security.txt in accordance with RFC 9116.

Found Something?

Tell us privately, tell us early, and we will handle it like professionals on both sides.

security@objexis.ai