Vulnerability Disclosure Policy (VDP) — Laruna
Version 1.0 · Effective: Jul 2026 · Owner: Laruna Director · Review: annually. Closes cross-check gap #6 (a security@ address existed, but no structured channel/policy). This is the human-readable policy; the machine-readable /.well-known/security.txt and repo SECURITY.md point here. Inbound reports route into the incident system (auto-open a record).
1 · Our commitment
We welcome reports of security vulnerabilities and treat the people who send them as allies. We commit to acknowledge, investigate, keep you updated, and fix confirmed issues promptly — and to not pursue legal action against good-faith researchers who follow this policy.
2 · How to report
- Email: security@laruna.ai
- Please include: what you found, where (URL/endpoint/parameter), how to reproduce it (steps, a proof-of-concept, or a short video), and the impact you believe it has.
- Encrypt sensitive details if you can; we can provide a key on request.
- Do not post the issue publicly, share it with third parties, or exploit it beyond the minimum needed to demonstrate it, until we've had a chance to fix it.
3 · What we promise (response targets)
| Stage | Target |
|---|---|
| Acknowledge your report | within 2 business days |
| Initial assessment + severity | within 5 business days |
| Fix or mitigation for confirmed High/Critical | on the incident SLA (P1 hours · P2 ≤48h) |
| Progress updates | at least every 7 days until resolved |
| Closure + (optional) credit | once fixed and, where relevant, re-tested |
Every report opens an incident record (T0 stamped), so the SLA clock and audit trail apply exactly as they do for any self-detected issue.
4 · Safe harbour (good-faith rules)
If you make a good-faith effort to follow this policy, we will consider your research authorised and will not pursue action against you. Good faith means you:
- Only interact with accounts you own or have explicit permission to test.
- Do not access, modify, or exfiltrate another tenant's or person's data — if you can reach it, stop, and tell us; a redacted proof is enough.
- Avoid privacy violations, service degradation/denial-of-service, spam, or destruction of data.
- Give us reasonable time to remediate before any public disclosure (we aim to agree a coordinated timeline with you).
5 · Scope
- In scope: the Laruna platform and its public web app + API (laruna.ai and tenant instances you're authorised to test), authentication/session/2FA, and multi-tenant isolation.
- Out of scope: denial-of-service/volumetric attacks, social engineering of staff or clients, physical attacks, findings only exploitable via a rooted/jailbroken device or outdated browser, automated scanner output without a demonstrated impact, and third-party services we don't operate (report those to the relevant vendor).
6 · Rewards
We do not run a paid bug-bounty at this time. We're glad to credit reporters (with your consent) in a security acknowledgements list and to provide written confirmation of your responsible disclosure.