Vulnerability Disclosure Policy

At Aurigo, safeguarding the security and integrity of our applications and customer data is a top priority. We welcome and encourage responsible security researchers to report vulnerabilities they discover in our systems. This Vulnerability Disclosure Policy (VDP) provides clear guidelines for conducting security research and reporting potential vulnerabilities in a manner that protects users and supports coordinated disclosure.

We appreciate your efforts to improve the safety and resilience of our services and will make every effort to review and respond to reports promptly.

Authorization

If you make a good faith effort to comply with this policy during your security research, we consider your research to be authorized. Aurigo will not pursue legal action against you. If a third party initiates legal action related to your compliant research activities, we will make our authorization known.

We are committed to working with researchers to understand, validate, and remediate reported vulnerabilities.

Scope

The following Aurigo domains are currently in scope

Out of scope

  • Customer specific application instances and data.
  • Internal facing systems not listed above.
  • Third party services integrated with Aurigo products.
  • Any system not listed above.

Before beginning any testing, please verify that the target is explicitly within the defined scope. If you are uncertain whether a system is in scope, reach out to security@aurigo.com for clarification.

Rules of engagement

To ensure the safety and privacy of our users and infrastructure, we ask all researchers to adhere to the following guidelines:

  • Avoid degradation of service, denial of service (DoS/DDoS), or any testing that may impact the availability of systems
  • Do not access or modify data that does not belong to you
  • Avoid phishing, social engineering, or physical intrusion attempts.
  • Do not spam or overload forms and input fields.
  • Only create one trial/test account per researcher. Contact us if more are needed.
  • Do not violate the applicable laws or regulations.

If sensitive or user data is inadvertently accessed, testing must stop immediately, and you must contact us without further distribution or use of the data.

Reporting a vulnerability

To report a security vulnerability, please email security@aurigo.com. Reports may be submitted anonymously; however, providing contact information will allow us to communicate and collaborate with you throughout the triage and resolution process.

Please include the below listed items in your report.

  • Description of the vulnerability and its potential impact.
  • Domain or service where the issue was discovered.
  • Steps to reproduce (screenshots, code samples, or proof-of-concept scripts are encouraged).
  • Any recommendations or suggested mitigations.

We commit to acknowledging your report within 5 business days and will strive to keep you informed of status updates and final remediation.

What to expect from Aurigo

  • A prompt acknowledgment within 5 business days.
  • Open communication throughout validation, triage, and remediation
  • A reasonable remediation timeline based on severity and complexity
  • Notification upon issue closure

If you wish to disclose the vulnerability publicly, we request coordinated disclosure discussions first.

While we do not offer monetary bounties or rewards for reported vulnerabilities, we greatly value your contribution and may acknowledge valid, impactful submissions (with your consent) on a future recognition page.

Non-qualifying vulnerabilities

The below types of issues are currently not in scope for this program and will generally not receive a response:

  • Email spoofing or misconfigured SPF/DMARC.
  • Missing security headers unless exploitable (e.g., HSTS).
  • Clickjacking on non-sensitive pages
  • Login/logout CSRF
  • Missing DNSSEC or CAA records.
  • Self-XSS or XSS requiring user manipulation or external link access.
  • Weak password policies.
  • Lack of rate limiting unless it results in a valid exploit.
  • Vulnerabilities in third-party libraries without a working exploit.
  • Browser history caching issues
  • Open redirects without demonstrable harm.

If you have questions, need clarification, or would like to offer suggestions on improving this policy, please contact us at security@aurigo.com.

Get in touch

Connect with us to scale up the potential of your programs
Contact us