Astraea-Pro · Responsible Disclosure & Quarterly RLS Audit
Astraea-Pro handles sensitive legal and therapeutic data. We take security seriously and welcome responsible disclosure from security researchers who identify vulnerabilities in our platform.
We follow a 90-day coordinated disclosure model. We will not pursue legal action against researchers who act in good faith and follow the guidelines below.
Response Time
Initial acknowledgement within 48 hours
Full remediation within 90 days
Please include in your report:
In Scope
Out of Scope
We will not pursue legal action against researchers who:
Note: This safe harbour applies only to security research conducted in accordance with this policy. Malicious exploitation of vulnerabilities is not covered.
| Severity | Examples | Response SLA |
|---|---|---|
| Critical | RLS bypass, auth bypass, mass data exposure | 24 hours |
| High | Privilege escalation, stored XSS, IDOR | 7 days |
| Medium | Reflected XSS, CSRF, information leakage | 30 days |
| Low | Missing headers, verbose errors, minor misconfigs | 90 days |