English

Places to contact

Moonshot AI

Type
AI company
Place
China
Last checked
2026-09-22
Next check due
2027-03-21

Ways to reach them

  • Security reports · Email address
    Limited contact route · 2026-09-22

    Who may use it: users-meeting-published-eligibility

    Restrictions: Confirmed by a Moonshot staff member relaying their Security Team on the official forum: 'If you discover any potential security issues, please report them to us at: security@moonshot.ai. We kindly ask that you follow responsible disclosure practices and give us reasonable time to investigate and address any finding…'

    Evidence that this route accepts contact · 2026-09-22

    Confirmed by a Moonshot staff member relaying their Security Team on the official forum: 'If you discover any potential security issues, please report them to us at: security@moonshot.ai. We kindly ask that you follow responsible disclosure practices and give us reasonable time to investigate and address any finding…'

    Moonshot confirmed in the same thread that it has NO public bug bounty and NO formal vulnerability disclosure policy.

  • Moonshot / Kimi developer forum · Web form
    Limited contact route · 2026-09-22

    Who may use it: users-meeting-published-eligibility

    Restrictions: Public forum where staff do respond.

    Evidence that this route accepts contact · 2026-09-22

    Public forum where staff do respond.

    Documented as the escalation route that actually works when email does not.

  • Homepage · Homepage
    Verification expired

    Evidence that this route accepts contact

  • No published frontier safety framework found · Published policy or framework
    Verification expired

    Evidence that this route accepts contact

What it does

No publicly named safety or alignment function. A security team exists and responds via the developer forum; Kimi models are released open-weight and via API.

Honest assessment

Rare documented case of a channel failing and a workaround succeeding. A security researcher posted on forum.moonshot.ai after emailing security@moonshot.ai and waiting 90 days with no response; a Moonshot staff member (yuikns) then replied on the forum within the thread, relaying the Security Team's confirmation of the address and of the absence of any formal VDP. The lesson is explicit: the email exists, went unanswered for three months, and a public post got a reply.

Notes

Email security@moonshot.ai, but plan to escalate to the public forum if you get nothing — that is the documented path to a human. No safe harbour, no bounty, no whistleblower channel. Nothing covers model safety as distinct from security.

Sources

Something wrong here?