AuditRailsAuditRails

Responsible disclosure policy

If you find a security vulnerability, please report it to us responsibly rather than opening a public GitHub issue.

Scope

This policy covers:

  • The AuditRails dashboard
  • The ingestion API
  • The processing worker
  • All official SDKs (Node.js, PHP, Python, Go)
  • Our infrastructure configuration

Safe harbor

We will not pursue legal action against good-faith security research conducted under this policy. To stay in scope: report a vulnerability as soon as you find it, avoid accessing or modifying data that isn't yours (including other customers' data), avoid actions that could degrade service for others (no automated scanning against production without contacting us first), and give us a reasonable window to fix an issue before any public disclosure.

Response SLA by severity

SeverityResponse timeFix deadlineNotification
Critical (CVSS 9.0+)4 hours24 hoursImmediate customer notification
High (CVSS 7.0-8.9)24 hours7 daysWeekly security digest
Medium (CVSS 4.0-6.9)72 hours30 daysMonthly security report
Low (CVSS 0.1-3.9)1 week90 daysQuarterly review

Report a vulnerability

Email us directly. We acknowledge every report within 24 hours.

security@auditrails.io

Back to the security page