LEGAL · SECURITY

Security & Responsible Disclosure

How we approach security, what we do not claim, and how to report a vulnerability to us.

1. Our approach

AuraGrid is designed around governance: each customer workspace is separated, access follows least privilege, credentials are protected, consequential actions can require approval, and results are verified before they are reported as complete. Security is a shared responsibility. Customers control their users, permissions, connected accounts and the data they send.

2. Controls

3. Certifications and status

AuraGrid is a new company. We do not currently claim SOC 2, ISO 27001 or similar certifications. If that changes, we will say so here. Customer-facing security questionnaires and further information are available on request.

4. Report a vulnerability

If you believe you have found a security issue, please tell us privately before sharing it publicly. Include enough detail to reproduce it, such as the address, steps, and the potential impact. We will acknowledge your report, keep you informed, and aim to fix confirmed issues quickly.

We will not pursue legal action against good-faith research that follows this policy. We do not currently run a paid bug-bounty program.

Security reports
Asia, including Bangladesh
Company
Postal address