Security Contact
We take security seriously. If you’ve discovered a potential vulnerability in AUDT, please let us know immediately through responsible disclosure. We appreciate the security community’s help in keeping AUDT safe.
Security vulnerabilities and questions
security@audt.techResponsible Disclosure Policy
AUDT operates a responsible disclosure programme. If you discover a security vulnerability, we ask that you:
- 1Email security@audt.tech with a clear description of the vulnerability, steps to reproduce, and potential impact.
- 2Give us reasonable time to investigate and patch before any public disclosure. We request a minimum of 90 days for critical issues.
- 3Do not access, modify, or delete customer data. If you encounter customer data during research, stop immediately and report it.
- 4Do not conduct denial-of-service attacks, social engineering, or physical security testing.
- 5Do not disclose the issue to others before we have issued a fix.
Response SLA
In-Scope & Out-of-Scope
In Scope
- · audt.tech and lekha-os.vercel.app
- · API endpoints (/api/v1/*)
- · Authentication and session management
- · Data isolation and tenant boundaries
- · Encryption implementation
- · Authorization bypasses
Out of Scope
- · Denial of service attacks
- · Social engineering
- · Physical security
- · Third-party services (Supabase, Vercel, Google)
- · Automated scanning without prior approval
- · Issues in client-side libraries not used by AUDT
Bug Bounty
AUDT appreciates responsible disclosure. We recognise security researchers who help us improve the platform with public acknowledgement (with your permission) and, for significant findings, financial rewards at our discretion.
We are in the process of establishing a formal bug bounty programme via a third-party platform. In the interim, please contact security@audt.tech to discuss findings and recognition.
PGP Encryption
For sensitive disclosures, you may encrypt your email using our security team’s PGP key. Key publication is in progress — email us directly and we will share the key on request.
Fingerprint: Email security@audt.tech to request
Other Security Inquiries
For general security questions, compliance documentation requests (SOC 2 reports, penetration test summaries, DPDP impact assessments), or enterprise security reviews, contact us at: