Security
Responsible Disclosure
Last updated: June 17, 2026 · Version 0.1 (DRAFT)
How to report
dhinagaran.s@airavadwebsolutions.com
Machine-readable contact: /.well-known/security.txt (RFC 9116). Please include steps to reproduce, affected URLs/endpoints, and impact. Do not include real customer data.
Scope & rules
- In scope: the AirOne web application, public APIs, and the marketing website.
- Test only against your own account/data — never another customer’s.
- No denial-of-service, spam, social engineering, or physical attacks.
- Give us reasonable time to remediate before any public disclosure.
What not to do
- Do not access, modify, or delete data that is not yours.
- Do not run automated scanners that degrade the Services.
- Do not extort, threaten, or demand payment for a report.
Safe harbor
If you make a good-faith effort to comply with this policy, we will not pursue or support legal action against you for your research, and we will work with you to understand and resolve the issue quickly.
What to expect
We acknowledge reports within a few business days, triage and validate them, keep you updated on remediation, and credit reporters who wish to be named once the issue is fixed.