English

Places to contact

Thinking Machines Lab

Type
AI company
Place
United States — USA
Last checked
2026-09-22
Next check due
2027-03-21

Ways to reach them

  • Security vulnerability reports · Email address
    Limited contact route · 2026-09-22

    Who may use it: users-meeting-published-eligibility

    Restrictions: Security vulnerabilities in systems, services and infrastructure. PGP key at https://thinkingmachines.ai/.well-known/pgp-key.txt (fingerprint 4FA9 136F 8F68 DDFD 1E78 6EBE CB0B 7A1E 3028 4CB4).

    Evidence that this route accepts contact · 2026-09-22

    Security vulnerabilities in systems, services and infrastructure. PGP key at https://thinkingmachines.ai/.well-known/pgp-key.txt (fingerprint 4FA9 136F 8F68 DDFD 1E78 6EBE CB0B 7A1E 3028 4CB4).

    Verified by decoding the Cloudflare-obfuscated addresses in the page source. Explicitly no bug bounty: 'we do not operate a bug bounty program and do not offer monetary rewards or compensation of any kind'.

  • Model safety incidents — routed to Legal · Email address
    Limited contact route · 2026-09-22

    Who may use it: users-meeting-published-eligibility

    Restrictions: The disclosure policy states: 'This policy does not cover model safety. To report an incident related to Inkling, please contact us at [legal@thinkingmachines.ai].'

    Evidence that this route accepts contact · 2026-09-22

    The disclosure policy states: 'This policy does not cover model safety. To report an incident related to Inkling, please contact us at [legal@thinkingmachines.ai].'

    Significant finding: model safety is carved out of the security process and sent to the legal department. Verified by decoding the page source.

  • Homepage · Homepage
    Verification expired

    Evidence that this route accepts contact

  • No frontier safety framework published; Coordinated Vulnerability Disclosure Policy is the only governance document · Published policy or framework
    Verification expired

    Evidence that this route accepts contact

What it does

States it will contribute to AI safety by 'maintaining a high safety bar—preventing misuse of our released models while maximizing users' freedom', sharing best practices, and 'accelerating external research on alignment by sharing code, datasets, and model specs'. No named safety team.

Honest assessment

Too new for public accounts of responsiveness. The structural signal is clear though: Thinking Machines writes an unusually strong safe-harbour clause for security research and then explicitly excludes model safety from it, routing model-safety incidents to legal@ — which means a model-safety report arrives at a desk whose job is liability, and arrives outside the protections the same page grants to security researchers.

Notes

The safe harbour is one of the best-written in this list, but read its boundary: 'When you conduct security research and vulnerability disclosure in good faith and in compliance with this policy, we consider that research to be authorized, and we will: Not pursue or support any legal action against you for accidental, good-faith violations of this policy, including under the Computer Fraud and Abuse Act or the anti-circumvention provisions of the Digital Millennium Copyright Act; Waive any restrictions in our Terms of Service or Acceptable Use Policy...; and If a third party initiates legal action against you..., take reasonable steps to make it known that your actions were authorized.' None of that covers a model-safety finding. Get advice before sending a jailbreak to legal@.

Sources

Something wrong here?