Policy
Last updated 2026-08-10
Auroranexis maintains a coordinated vulnerability disclosure process. Report issues to security@auroranexis.com. Machine-readable contact details are published at /.well-known/security.txt.
A. Purpose
Auroranexis maintains a coordinated vulnerability disclosure process so researchers and customers can report security issues responsibly.
This policy explains how to report a vulnerability, what is in scope, what testing is prohibited, and how we aim to respond. It is an operational process description — not a compliance certification and not a contractual service-level agreement.
B. How to report a vulnerability
Email security@auroranexis.com with the subject line starting with “[Security]” when possible.
Do not open a public issue, do not publish exploit details before coordinated disclosure, and do not include live passwords, session tokens, or unnecessary personal data in the initial report.
C. Required report information
Please include as much of the following as you can safely share:
- Affected URL, hostname, or component
- Vulnerability type (for example: broken access control, injection, misconfiguration)
- Impact assessment
- Step-by-step reproduction instructions
- Proof of concept only if it is safe and does not harm other users or production availability