← Trust & Security

Security policy

Coordinated vulnerability disclosure

We use vulnerability research to help maintainers fix real problems, not to embarrass them. This policy explains how we handle vulnerabilities we find in other people’s software and how to report a suspected vulnerability in Xora.

Last updated: August 31, 2026

When Xora finds a vulnerability

We manually validate any finding we intend to disclose. Once it is confirmed, we contact the maintainer through the project’s stated security channel, its SECURITY.md, a security address, or an appropriate vulnerability coordinator. We report privately before we say anything in public.

Our report includes the affected component and version, the demonstrated impact, reproducible evidence, and enough remediation detail to act. We also contribute at least one of the following: a patch, a regression test, or written remediation specific enough to implement.

The coordination window

Our disclosure window is 90 days by default, or shorter where the maintainer agrees. The clock starts when we send a complete private report through a published or otherwise reasonable security channel.

  1. 01 · Report

    Private first

    We send the validated finding, reproduction, evidence, and our remediation contribution to the maintainer.

  2. 02 · Coordinate

    Fix and verify

    We answer questions, retest the remediation where possible, and coordinate advisory or CVE details when they apply.

  3. 03 · Publish

    No surprises

    Publication follows when the fix ships or the agreed window closes, whichever comes first.

Courtesy review before publication

Before publication, we send the maintainer the planned date and the technical material we intend to publish. We invite factual and technical corrections and offer to include the maintainer’s statement. This is a courtesy review, not a transfer of editorial control, but it means the maintainer is not surprised by what ships.

If a maintainer does not respond

We retry the original channel and look for another documented security contact. If that fails, we escalate to the project or organization owner and, where appropriate, an ecosystem security team or a neutral vulnerability coordinator such as CERT/CC.

Silence does not restart the coordination window. If it closes without a response, we may publish so users can assess and reduce their exposure. We limit the disclosure to details that serve that purpose and withhold unnecessary exploit detail where publishing it would create risk without helping defenders.

What publication is for

We publish to give users an accurate account of the vulnerability, its impact, and its remediation. We do not publish to embarrass a maintainer, manufacture conflict, or score a response. Our writing focuses on the technical condition and the fix, not blame. If we make a material error, we correct it.


Report a vulnerability in Xora

Email security@getxora.ai. We acknowledge vulnerability reports within two business days.

Include the affected Xora service or URL, what you observed, steps to reproduce it, the impact you believe is possible, and any logs, screenshots, or proof-of-concept material that helps us validate it. Tell us how you would like to be credited, or that you prefer not to be named.

Minimize access to data, stop if you encounter customer or personal data, and do not disrupt the service. This reporting channel is not authorization to test Xora, its customers, or third-party systems.