Back to resources

Legal register

Vulnerability Disclosure Policy

Englishvulnerability-disclosure

AUVY · Legal registerEnglishvulnerability-disclosure

Version: 1.0 · Last updated: 2026-08-03

We welcome good-faith reports that help protect AUVY customers and services. This policy describes the coordinated disclosure path; it does not authorize access to data, systems, or accounts that you do not own.

Report securely

Email security@auvy.ai with:

  • the affected host, endpoint, or product area
  • clear reproduction steps and the observed impact
  • the minimum proof needed to demonstrate the issue
  • your preferred contact details and any disclosure deadline you propose

Do not include unnecessary personal data, customer content, credentials, or access tokens. If sensitive transfer is necessary, ask us to agree a protected channel first.

Good-faith research

Please:

  • use only accounts and data you own or are expressly authorized to test
  • stop and report immediately if you encounter third-party or customer data
  • avoid privacy violations, persistence, phishing, social engineering, malware, denial of service, destructive testing, automated high-volume scanning, and degradation of production
  • do not exfiltrate, alter, delete, retain, or publicly disclose data
  • allow reasonable time for validation and remediation before public disclosure

Production penetration tests, load tests, and broad vulnerability scans require AUVY’s prior written authorization.

Our response

We aim to acknowledge a complete report within five business days, validate it, keep the reporter informed of material progress, and coordinate disclosure based on risk and remediation status. Timelines may vary with complexity and third-party dependencies.

Where research follows this policy, is conducted in good faith, and is promptly reported, AUVY will not initiate legal action solely because of that research. This statement does not bind third parties or excuse violations of law, contracts, privacy, or rights of others.

Scope and rewards

AUVY’s internet-facing product and Trust Center are in scope unless a surface states otherwise. Third-party services, customer-selected integrations, and social-engineering targets are out of scope. AUVY does not currently operate a paid bug-bounty program.