Policy

Responsible Disclosure

How to report security issues affecting Aerod, its apps, redirect system, or website infrastructure.

Reporting security issues

If you believe you have found a security issue affecting Aerod, its apps, website, provider-link system, or deployment configuration, use the Aerod contact form with the Security vulnerability topic.

Include enough detail to reproduce and understand the issue.

Describe the issue clearly and avoid sending credentials, private keys, personal data, malware samples, or full data exports. The form accepts up to three PNG, JPEG, WebP, or PDF attachments totaling no more than 5 MB. If a sensitive proof is necessary, describe what you found first so a safer transfer method can be agreed before the material is sent.

What to include

A useful report usually includes:

  • Affected URL or route.
  • Steps to reproduce.
  • Expected behavior and actual behavior.
  • Browser, device, or network context if relevant.
  • Screenshots or proof-of-concept details that avoid harming users.

Testing boundaries

Do not access, modify, delete, or exfiltrate data that does not belong to you. Do not degrade service, run denial-of-service testing, attempt social engineering, or test third-party providers linked from Aerod without their permission.

Stop testing when you have enough evidence to demonstrate the issue. Do not establish persistence, evade access controls beyond what is necessary to confirm the report, publish user data, or use the finding to pressure Aerod or another party.

Scope

Reports should concern Aerod-controlled website routes, browser apps, redirect behavior, or deployment configuration. Vulnerabilities in a provider, analytics vendor, browser, hosting platform, or other third party should be reported through that organization's disclosure process unless the issue is specifically caused by Aerod's integration.

This policy does not grant authorization to test systems Aerod does not control, and it does not override applicable law, service terms, or third-party policies.

Response expectations

Aerod should acknowledge valid reports, investigate in good faith, and correct issues based on severity and practical impact.

Please allow a reasonable investigation period before public disclosure. Aerod may ask for clarification, a reduced proof of concept, or a retest after a fix. Reports that are automated noise, unrelated to Aerod, or unsupported by reproducible evidence may not receive an individual response.

This policy does not create a bug bounty program unless Aerod publishes one separately.