Authorized research pipeline

Snapshots,
not screenshots.

Authorized zip clones of AI platform workspaces — full state, reproducible, chain-of-custody intact. Built for security researchers working under formal bug bounty programs.

[ free ][ signed manifest ][ sha-256 ]
hg — workspace export
$ hg export --platform sogood --workspace ws-0x4a2f
→ fetching program scope… open
→ verifying authorization… confirmed
→ exporting workspace state…
→ packaging 312 objects (chat_history, files, integrations)
manifest.json
{
"platform": "sogood",
"scope": "bug_bounty_open",
"researcher": "handle:your-h1-handle",
"authorized": true,
"sha256": "a4f2e9c..."
}
✓ workspace-clone-ws-0x4a2f.zip
3.2 MB · delivered to researcher@email.com
process

Submit once. Receive a signed, reproducible artifact.

01

Submit your request

Provide your bug bounty handle, the target platform, and your active program scope URL.

02

Scope verification

We cross-check against the platform's published program. Every clone requires confirmed in-scope authorization.

03

Workspace export

The pipeline exports full workspace state: chat history, files, integrations, permission maps.

04

Signed delivery

You receive a zip with a manifest.json — scope reference, SHA-256 hash, researcher handle, timestamp.

platforms

Authorized platform coverage

Each platform requires a verified authorization basis before we process any export request.

S
authorized

SoGood Workspace Clone

Authorized zip clone of a SoGood AI platform workspace. Full state export — chat history, integrations, file attachments, permission configuration — packaged with a signed manifest and SHA-256 hash. SoGood's open bug bounty program authorizes this clone for registered researchers.

M
authorized

Multi-Platform Bundle

Request workspace clones across multiple authorized AI platforms in a single submission. Each platform export is scoped, authorized, and delivered as a separate signed zip with its own chain-of-custody manifest. Contact us to confirm platform coverage before submitting.

+
pending

More platforms

Additional authorized platforms are being verified and added to the pipeline.

authorization

Every zip ships with a chain-of-custody manifest.

We don't process requests outside a platform's published bug bounty scope. Before any export begins, scope is verified, logged, and embedded in the manifest — so your evidence is clean from the first byte.

Full authorization framework →
manifest.json

Scope reference, researcher handle, platform, export timestamp, and authorization basis — embedded in every zip.

SHA-256 hash

Deterministic hash of the zip contents. Verify integrity before attaching to your report.

Scope log

The exact program URL and asset class verified at time of export. Timestamped, immutable.

ready to submit

Your PoC should survive triage.

Free for academic and white-hat security researchers working under authorized programs.

Request a clone →

hollow-ground@sogoodmail.co

Built with