About · Trust, Safety & Compliance

Responsible Disclosure

Auliq recognizes that security researchers, customers, partners, employees, and members of the broader technology community may identify security vulnerabilities or weaknesses affecting Auliq products, services, websites, infrastructure, or systems.

Auliq encourages the responsible reporting of potential security vulnerabilities so that they can be evaluated, investigated, and addressed appropriately.

What to Report

Potentially reportable issues may include:

  • Authentication or authorization vulnerabilities
  • Access-control weaknesses
  • Data exposure or unintended information disclosure
  • Security vulnerabilities in applications or APIs
  • Cross-site scripting or injection vulnerabilities
  • Insecure configurations
  • Significant cryptographic weaknesses
  • Vulnerabilities affecting confidentiality, integrity, or availability
  • Other security weaknesses that could materially affect Auliq systems, customers, users, or information

Responsible Reporting

Security researchers and other reporters are encouraged to:

  • Provide sufficient information to reproduce and investigate the issue
  • Report vulnerabilities as soon as reasonably practical after discovery
  • Avoid accessing, modifying, deleting, or retaining data that does not belong to them
  • Avoid actions that could unnecessarily disrupt services or systems
  • Avoid testing against other users or customer environments
  • Avoid publicly disclosing a vulnerability before Auliq has had a reasonable opportunity to investigate and address it
  • Protect any information obtained during responsible security testing

What to Include

Where possible, a report should include:

  • A description of the vulnerability
  • The affected product, service, application, or endpoint
  • Steps required to reproduce the issue
  • Relevant technical information
  • Potential impact
  • Supporting evidence or proof of concept where appropriate
  • Any suggested remediation information

Auliq's Response

Auliq will seek to review legitimate vulnerability reports and, where appropriate, investigate, validate, prioritize, remediate, and monitor reported issues.

Response times and remediation timelines may vary according to the nature, severity, complexity, and potential impact of the issue.

Auliq may communicate with the reporter during the investigation when additional information is required or when appropriate updates can be provided.

Responsible Disclosure Principles

Auliq supports responsible security research conducted in a manner that respects customer information, user privacy, system availability, intellectual property, and applicable requirements.

Auliq may establish additional security reporting procedures, security contact channels, or vulnerability disclosure programs for specific products or services.