Aurix
Aurix Governance Risk Compliance
← Back to Aurix Log in

Security & Vulnerability Disclosure Policy

Effective date: September 5, 2026 · Last reviewed: September 5, 2026

Aurix GRC is a product of Xaephyr Reliance Group KK ("XRG," "we," "us," "our"), a Japan-based managed IT and technology services company. This policy applies to the Aurix GRC website and platform, and is maintained consistently with XRG's group-wide legal and privacy practices.

As a platform built and operated by a managed IT and cybersecurity services provider, Aurix holds itself to the same standard XRG advocates for its customers. If you believe you've found a security vulnerability affecting this website or platform, we want to hear from you, and we commit to working with good-faith researchers in a respectful, non-adversarial way.

1. Our Commitment

  • We will acknowledge receipt of a good-faith report within 30 business days.
  • We will investigate promptly and keep you reasonably informed of progress.
  • We will not pursue legal action against researchers who make a good-faith effort to comply with this policy.

2. Scope

In scope for this policy:

  • This website and platform (aurixgrc.com and app.aurixgrc.com) and their directly associated infrastructure.

Out of scope:

  • Data or accounts belonging to other Aurix customer organizations — do not attempt to access another organization's workspace, even if a vulnerability appears to allow it; report it to us immediately instead.
  • Third-party services we rely on but do not operate ourselves (for example, our hosting, AI model, email delivery, or font providers) — please report those issues directly to the relevant provider.
  • Denial-of-service testing, spam, or any testing that degrades service for other customers.
  • Social engineering or phishing attempts directed at XRG or customer staff.
  • Physical security testing of any XRG facility.

3. Rules of Engagement

  • Only test against explicitly in-scope assets listed above.
  • Do not access, modify, or exfiltrate data that does not belong to you. Stop and report immediately if you encounter data that appears to belong to another organization.
  • Do not run automated scanning tools at a volume or rate that could degrade service availability.
  • Do not attempt to pivot from a discovered vulnerability into further exploitation beyond what is necessary to demonstrate impact (proof of concept only).
  • Give us reasonable time to remediate before any public disclosure (see Section 6, Coordinated Disclosure).

4. How to Report

Send a report to [email protected] including:

  • A clear description of the vulnerability and its potential impact.
  • Step-by-step reproduction instructions, including the specific URL, endpoint, or component affected.
  • Proof-of-concept detail (screenshots, request/response captures, or a short video) sufficient to verify the issue without unnecessary further exploitation.
  • Your preferred contact method for follow-up.

5. What Happens Next

  • We acknowledge your report and assign it a severity rating.
  • We investigate and validate the finding, contacting you if we need more information.
  • We develop and deploy a remediation, and let you know once it's resolved.
  • Where appropriate and with your permission, we credit researchers who report valid, previously unknown issues (see Section 6).

6. Coordinated Disclosure & Recognition

We ask that you give us a reasonable opportunity to investigate and remediate a reported issue before any public disclosure — typically 90 days from acknowledgment, subject to extension for complex issues by mutual agreement. With your permission, we're happy to publicly credit researchers who responsibly report a valid, previously unreported vulnerability.

7. Safe Harbor

Activity conducted in good faith and in accordance with this policy is considered authorized. We will not initiate legal action, and will work to prevent legal action from being taken by others, in connection with research conducted consistently with this policy. This safe harbor applies only to the scope defined in Section 2, and only where the Rules of Engagement in Section 3 are followed.

8. Contact

Security reports and general questions about this policy can be sent to [email protected].

Aurix Aurix
Privacy Policy Cookie Policy Security Contact
© 2026 Aurix, a product of Xaephyr Reliance Group. Not a substitute for a certified security or legal audit.