Responsible Disclosure Policy
Effective 2 September 2026 · Auric 1.3.0-beta.1
In plain English: found a security issue? Tell us privately at security@auric.cx and give us time to fix it. Act in good faith and don't harm users' data, and we won't pursue legal action against you.
1. Purpose and Scope
This Policy encourages coordinated disclosure of vulnerabilities in the Services. It covers auric.cx, the Application and CLI, and Auric-controlled infrastructure — not third-party providers, which should be reported to them. Capitalized terms follow Auric's Master Definitions in the Terms of Service.
2. How to Report
Email security@auric.cx with steps to reproduce, the affected component, and the impact. There is no bug-bounty programme and no monetary reward — we would rather tell you that up front than have you find out after the work. We will credit you publicly if you would like us to.
3. Safe Harbor
If you make a good-faith effort to comply with this Policy, we will not pursue or support legal action against you for your research, and we will treat it as authorized under applicable computer-misuse law. This does not authorize actions against third parties or other users.
4. Rules of Engagement
Do:
- test only your own accounts and data;
- use the least-impactful methods necessary;
- report promptly; and
- keep findings confidential until we have resolved them.
Do not:
- access, modify, or exfiltrate data that is not yours;
- degrade the Services (no denial-of-service or spam);
- use social engineering or physical attacks; or
- disclose publicly before we agree.
5. Our Commitment
We aim to acknowledge your report within five business days, triage it, keep you informed as it moves, and credit you if you wish. We coordinate public disclosure once a fix is available.
6. Contact
security@auric.cx.
Document control
| Field | Value |
|---|---|
| Document ID | AUR-LEG-007 |
| Applies to | Auric 1.3.0-beta.1 — private beta |
| Status | Published — private beta |
| Owner | Auric |
| Review frequency | Quarterly during beta, or on material change |
| Related documents | Security (006), Acceptable Use (004), Terms (001) |
| Applies to | Auric 1.3.0-beta.1 — private beta |
Change log
2 September 2026: The beta is described as private throughout, which is how access is actually granted — requested, confirmed, then opened in waves. No right, obligation, party or data practice changed.
1.3.0-beta.1 (2026-08-02): Published for the private beta. Review markers resolved against the implementation, unsupported AI-provider claims removed, and retention stated from the constants that enforce it.
© 2026 Auric. All rights reserved.