Responsible Disclosure Policy
Draft v0.1.0 · Not yet in force · Last updated 2026-07-23
Draft for review. This is a pre-launch draft pending review by qualified legal counsel. Items marked [FD-…] / [IA-…] are pending and not yet in force.
In plain English: found a security issue? Tell us privately at security@auric.cx and give us time to fix it. Act in good faith and don't harm users' data, and we won't pursue legal action against you.
1. Purpose and Scope
This Policy encourages coordinated disclosure of vulnerabilities in the Services. It covers auric.cx, the Application and CLI, and Auric-controlled infrastructure — not third-party providers, which should be reported to them. Capitalized terms follow Auric's Master Definitions in the Terms of Service.
2. How to Report
Email security@auric.cx [FD-013] with steps to reproduce, the affected component, and the impact. Whether a bug-bounty or reward program applies is set by [FD-015]; by default there is no monetary reward during the beta, and recognition is available on request.
3. Safe Harbor
If you make a good-faith effort to comply with this Policy, we will not pursue or support legal action against you for your research, and we will treat it as authorized under applicable computer-misuse law. This does not authorize actions against third parties or other users.
4. Rules of Engagement
Do:
- test only your own accounts and data;
- use the least-impactful methods necessary;
- report promptly; and
- keep findings confidential until we have resolved them.
Do not:
- access, modify, or exfiltrate data that is not yours;
- degrade the Services (no denial-of-service or spam);
- use social engineering or physical attacks; or
- disclose publicly before we agree.
5. Our Commitment
We will acknowledge your report within [FD-015] (target: five business days), triage it, keep you informed, and credit you if you wish. We coordinate public disclosure after a fix is available.
6. Contact
security@auric.cx [FD-013].
Document control
| Field | Value |
|---|---|
| Document ID | AUR-LEG-007 |
| Version | 0.1.0 |
| Status | Draft — Pre-Counsel Review |
| Owner | Auric [FD-013] |
| Review frequency | Quarterly during beta, or on material change |
| Related documents | Security (006), Acceptable Use (004), Terms (001) |
| Applies to | Auric Closed Beta — all deployment models |
Change log
v0.1.0 (2026-07-23): Initial draft.
© 2026 Auric. All rights reserved.