Responsible disclosure policy
If you find a security vulnerability, please report it to us responsibly rather than opening a public GitHub issue.
Scope
This policy covers:
- The AuditRails dashboard
- The ingestion API
- The processing worker
- All official SDKs (Node.js, PHP, Python, Go)
- Our infrastructure configuration
Safe harbor
We will not pursue legal action against good-faith security research conducted under this policy. To stay in scope: report a vulnerability as soon as you find it, avoid accessing or modifying data that isn't yours (including other customers' data), avoid actions that could degrade service for others (no automated scanning against production without contacting us first), and give us a reasonable window to fix an issue before any public disclosure.
Response SLA by severity
| Severity | Response time | Fix deadline | Notification |
|---|---|---|---|
| Critical (CVSS 9.0+) | 4 hours | 24 hours | Immediate customer notification |
| High (CVSS 7.0-8.9) | 24 hours | 7 days | Weekly security digest |
| Medium (CVSS 4.0-6.9) | 72 hours | 30 days | Monthly security report |
| Low (CVSS 0.1-3.9) | 1 week | 90 days | Quarterly review |
Report a vulnerability
Email us directly. We acknowledge every report within 24 hours.
security@auditrails.io