DeepSeek
- Type
- AI company
- Place
- China
- Last checked
- 2026-09-22
- Next check due
- 2027-03-21
Ways to reach them
- Security
- General service contact
- Homepage
- Safe Use Policy (no frontier safety framework published)
What it does
No publicly named safety or alignment function. Safe Use Policy governs the hosted service; the company publishes research papers but no safety framework.
Honest assessment
DeepSeek has been the subject of an unusual volume of external security and safety findings — Wiz Research found a publicly exposed ClickHouse database leaking chat history in January 2025, and Cisco's red-teaming reported a 100% attack success rate against R1 on a standard harmful-prompt benchmark. In none of these widely covered cases did the researchers describe a functioning coordinated-disclosure exchange with DeepSeek; Wiz described reaching out and the exposure being closed quickly, but there is no published disclosure process. No bug bounty, no VDP, no safe harbour.
Notes
security@deepseek.com is genuinely published, which puts DeepSeek ahead of several Western labs on the narrow question of having an address. But there is no policy behind it — no scope, no commitment, no safe harbour. Assume anything you send is unprotected and may not be acknowledged.