Responsible Disclosure Policy
Last updated: August 29, 2026
AuditGate exists to help teams find and fix vulnerabilities before attackers do, so we take security research seriously, including research aimed at us. If you believe you've found a security vulnerability in AuditGate, we want to hear from you.
1. Scope
In scope for this policy:
- auditgate.io and its subdomains
- The AuditGate dashboard and API, once generally available
Out of scope:
- Third-party services we integrate with but do not operate (e.g. GitHub, Slack, Jira)
- Denial-of-service, spam, or volumetric attacks
- Social engineering of our staff, contractors, or users
- Physical attacks against our offices or infrastructure providers
- Automated scanning that generates significant traffic without prior coordination
2. Guidelines
When testing, please:
- Avoid accessing, modifying, or exfiltrating data that isn't your own.
- Avoid degrading the availability of the Service for other users.
- Give us a reasonable amount of time to investigate and remediate before disclosing publicly.
- Only interact with test accounts you own, or ask us for a sanctioned test environment.
3. How to Report
Email [email protected] with as much detail as you can provide:
- A description of the vulnerability and its potential impact
- Steps to reproduce, including any proof-of-concept
- The URL, endpoint, or component affected
- Any tools or scripts used
Please encrypt sensitive reports where possible, and avoid including real customer data in your report.
4. What to Expect From Us
- We will acknowledge your report within 3 business days.
- We will investigate and keep you informed of our progress at reasonable intervals.
- We will let you know once a fix has been shipped, and credit you (if you'd like) once resolved.
5. Safe Harbor
We will not pursue legal action against researchers who discover and report vulnerabilities in good faith, in accordance with this policy. This safe harbor applies only to testing conducted within the scope and guidelines described above.
6. Recognition
AuditGate does not currently operate a paid bug bounty program. We are happy to publicly credit researchers who report valid issues, with your permission, once a fix has shipped.


