Security disclosure policy
We welcome good-faith security research. This page describes how to report a vulnerability in Alusia and what you can expect from us.
1. How to report
Report suspected vulnerabilities as soon as possible via security@alusia.net. Include steps to reproduce, the affected URL or component, and, if applicable, a proof of concept. Please do not publish details before we have confirmed a fix.
2. Scope
In scope: alusia.net, the application under it, and Alusia-operated APIs. Out of scope: denial-of-service testing (DoS), spam or social engineering of Alusia staff or customers, physical attacks, and third-party services we do not operate (report those to the respective provider). Use only accounts and organizations you created for testing; never access, modify, or exfiltrate another customer’s data - if a flaw exposes such data, stop and report immediately.
3. What we commit to
We acknowledge reports promptly, keep you informed of remediation progress, and credit researchers who wish to be named once the issue is resolved. We do not operate a paid bounty program at this time.
4. Good-faith research
We will not pursue legal action for security research conducted in good faith within this policy: without harming users or data, without service disruption, respecting proportionality, and giving us reasonable time to remediate before any disclosure.
Questions about these documents can be sent through the contact page while the dedicated legal address is being set up. alusia.net/en/contact