Security Contact

We take security seriously. If you’ve discovered a potential vulnerability in AUDT, please let us know immediately through responsible disclosure. We appreciate the security community’s help in keeping AUDT safe.

Security vulnerabilities and questions

security@audt.tech

Responsible Disclosure Policy

AUDT operates a responsible disclosure programme. If you discover a security vulnerability, we ask that you:

  1. 1Email security@audt.tech with a clear description of the vulnerability, steps to reproduce, and potential impact.
  2. 2Give us reasonable time to investigate and patch before any public disclosure. We request a minimum of 90 days for critical issues.
  3. 3Do not access, modify, or delete customer data. If you encounter customer data during research, stop immediately and report it.
  4. 4Do not conduct denial-of-service attacks, social engineering, or physical security testing.
  5. 5Do not disclose the issue to others before we have issued a fix.

Response SLA

CriticalAcknowledge within 4 hours · Initial fix within 24 hours · Full resolution within 7 days
HighAcknowledge within 24 hours · Resolution within 14 days
MediumAcknowledge within 48 hours · Resolution within 30 days
LowAcknowledge within 72 hours · Resolution within 90 days

In-Scope & Out-of-Scope

In Scope

  • · audt.tech and lekha-os.vercel.app
  • · API endpoints (/api/v1/*)
  • · Authentication and session management
  • · Data isolation and tenant boundaries
  • · Encryption implementation
  • · Authorization bypasses

Out of Scope

  • · Denial of service attacks
  • · Social engineering
  • · Physical security
  • · Third-party services (Supabase, Vercel, Google)
  • · Automated scanning without prior approval
  • · Issues in client-side libraries not used by AUDT

Bug Bounty

AUDT appreciates responsible disclosure. We recognise security researchers who help us improve the platform with public acknowledgement (with your permission) and, for significant findings, financial rewards at our discretion.

We are in the process of establishing a formal bug bounty programme via a third-party platform. In the interim, please contact security@audt.tech to discuss findings and recognition.

PGP Encryption

For sensitive disclosures, you may encrypt your email using our security team’s PGP key. Key publication is in progress — email us directly and we will share the key on request.

Key ID: Coming soon
Fingerprint: Email security@audt.tech to request

Other Security Inquiries

For general security questions, compliance documentation requests (SOC 2 reports, penetration test summaries, DPDP impact assessments), or enterprise security reviews, contact us at: