English

Places to contact

IBM

Type
AI company
Place
United States — USA
Last checked
2026-09-22
Next check due
2027-03-21

Ways to reach them

  • IBM PSIRT · Email address
    Limited contact route · 2026-09-22

    Who may use it: users-meeting-published-eligibility

    Restrictions: 'Potential security and AI vulnerabilities in IBM products and websites.' AI vulnerabilities explicitly in scope. PGP available.

    Evidence that this route accepts contact · 2026-09-22

    'Potential security and AI vulnerabilities in IBM products and websites.' AI vulnerabilities explicitly in scope. PGP available.

    One of only a handful of PSIRTs to name AI vulnerabilities in its remit.

  • IBM on HackerOne · Responsible disclosure programme
    Limited contact route · 2026-09-22

    Who may use it: users-meeting-published-eligibility

    Restrictions: Third-party researcher submissions.

    Evidence that this route accepts contact · 2026-09-22

    Third-party researcher submissions.

  • IBM Safe Harbor Policy · Responsible disclosure programme
    Limited contact route · 2026-09-22

    Who may use it: users-meeting-published-eligibility

    Restrictions: The PSIRT page states vulnerability reporting is 'protected by IBM Safe Harbor Policy', available as a downloadable document.

    Evidence that this route accepts contact · 2026-09-22

    The PSIRT page states vulnerability reporting is 'protected by IBM Safe Harbor Policy', available as a downloadable document.

    The full text is in a linked PDF rather than inline; read it before testing. Anonymous form submission is also offered.

  • Homepage · Homepage
    Verification expired

    Evidence that this route accepts contact

  • Responsible Technology / AI ethics principles (no frontier safety framework published) · Published policy or framework
    Verification expired

    Evidence that this route accepts contact

What it does

AI Ethics Board plus a Responsible Technology function governing watsonx and Granite models; PSIRT handles security and, unusually, explicitly names AI vulnerabilities in scope.

Honest assessment

No public accounts found of AI-specific reports to IBM PSIRT. IBM's AI Ethics Board is well-documented in its governance publications but is an internal review body with no published external intake. The PSIRT route is professional and long-established; whether a pure model-behaviour finding survives triage there is untested in public.

Notes

psirt@us.ibm.com is the route, and you can cite that AI vulnerabilities are in its published scope. There is no channel to the AI Ethics Board. IBM is one of the few here offering both anonymous submission and a written safe harbour policy.

Sources

Something wrong here?