Security
Not yet reviewed by a lawyer. This page explains in plain words how Aurnis works and what you can expect. It will be reviewed and may change before paid plans or public launch; if it changes in a way that matters to you, we will tell you.
Reporting a vulnerability
If you find a security problem in Aurnis, please tell us before telling anyone else: security@aurnis.com. Include what you found, how to reproduce it, and what it could allow. We will acknowledge it within 3 working days and keep you updated until it is fixed. If you want credit, tell us how you would like to be named.
Ground rules
- Use only accounts you created, and do not access, change or delete other people’s data. Stop as soon as you can show the problem.
- No denial-of-service, spam, social engineering of our staff or users, or physical attacks.
- Give us reasonable time to fix the issue before you share it.
Safe harbour
If you follow these rules and act in good faith, we will not take legal action against you, and we will work with you to fix the problem.
How we protect Aurnis
Access rules in the database limit every person to their own space and role. Files are private. Sensitive actions require signing in again, and optional two-step sign-in is available. We limit guessing attempts, keep an audit trail, and delete data on a published schedule. See the Privacy notice.