Skip to content
AIRAS Cloud

Trust

Vulnerability disclosure policy

AIRAS Cloud is operated by AFRH Consulting Limited (CRO 798243). We welcome coordinated reports from security researchers and testing providers.

How to report

Email security@airascloud.com with a description of the issue, the affected URL or endpoint, and the minimum steps needed to reproduce it. Our machine-readable contact record is published at /.well-known/security.txt.

We acknowledge every report within one business day, confirm whether we can reproduce it within five business days, and keep you informed until the issue is closed.

In scope

The AIRAS Cloud web application and its authenticated governance workspace, the Integration API, the invitation and role-assignment flows, the document upload and extraction pipeline, and the platform's session and second-factor handling.

Out of scope

Denial-of-service and volumetric testing, social engineering of staff or customers, physical security, findings in third-party managed infrastructure, and automated scanner output submitted without a demonstrated impact.

Rules we ask you to follow

Use only accounts and tenants you own or that we have provisioned for you. Do not access, modify, retain or disclose data belonging to any other tenant or individual.

Stop as soon as you have demonstrated a finding, and report any accidental exposure of customer data to us immediately and out of band.

Give us a reasonable period to remediate before any public disclosure, and coordinate the timing with us.

Our commitments

We will not pursue legal action against researchers who follow this policy in good faith. We will confirm the outcome, credit you if you wish to be named, and record the finding, the fix and the retest in our vulnerability register.

We do not currently operate a paid bounty. Serious findings are remediated on a priority basis and retested before the change is released.