English

Places to contact

DeepSeek

Type
AI company
Place
China
Last checked
2026-09-22
Next check due
2027-03-21

Ways to reach them

What it does

No publicly named safety or alignment function. Safe Use Policy governs the hosted service; the company publishes research papers but no safety framework.

Honest assessment

DeepSeek has been the subject of an unusual volume of external security and safety findings — Wiz Research found a publicly exposed ClickHouse database leaking chat history in January 2025, and Cisco's red-teaming reported a 100% attack success rate against R1 on a standard harmful-prompt benchmark. In none of these widely covered cases did the researchers describe a functioning coordinated-disclosure exchange with DeepSeek; Wiz described reaching out and the exposure being closed quickly, but there is no published disclosure process. No bug bounty, no VDP, no safe harbour.

Notes

security@deepseek.com is genuinely published, which puts DeepSeek ahead of several Western labs on the narrow question of having an address. But there is no policy behind it — no scope, no commitment, no safe harbour. Assume anything you send is unprotected and may not be acknowledged.

Sources

Something wrong here?