When Xora finds a vulnerability
We manually validate any finding we intend to disclose. Once it is confirmed, we contact the maintainer through the project’s stated security channel, its SECURITY.md, a security address, or an appropriate vulnerability coordinator. We report privately before we say anything in public.
Our report includes the affected component and version, the demonstrated impact, reproducible evidence, and enough remediation detail to act. We also contribute at least one of the following: a patch, a regression test, or written remediation specific enough to implement.
The coordination window
Our disclosure window is 90 days by default, or shorter where the maintainer agrees. The clock starts when we send a complete private report through a published or otherwise reasonable security channel.
01 · Report
Private first
We send the validated finding, reproduction, evidence, and our remediation contribution to the maintainer.
02 · Coordinate
Fix and verify
We answer questions, retest the remediation where possible, and coordinate advisory or CVE details when they apply.
03 · Publish
No surprises
Publication follows when the fix ships or the agreed window closes, whichever comes first.
Courtesy review before publication
Before publication, we send the maintainer the planned date and the technical material we intend to publish. We invite factual and technical corrections and offer to include the maintainer’s statement. This is a courtesy review, not a transfer of editorial control, but it means the maintainer is not surprised by what ships.
If a maintainer does not respond
We retry the original channel and look for another documented security contact. If that fails, we escalate to the project or organization owner and, where appropriate, an ecosystem security team or a neutral vulnerability coordinator such as CERT/CC.
Silence does not restart the coordination window. If it closes without a response, we may publish so users can assess and reduce their exposure. We limit the disclosure to details that serve that purpose and withhold unnecessary exploit detail where publishing it would create risk without helping defenders.
What publication is for
We publish to give users an accurate account of the vulnerability, its impact, and its remediation. We do not publish to embarrass a maintainer, manufacture conflict, or score a response. Our writing focuses on the technical condition and the fix, not blame. If we make a material error, we correct it.
Report a vulnerability in Xora
Email security@getxora.ai. We acknowledge vulnerability reports within two business days.
Include the affected Xora service or URL, what you observed, steps to reproduce it, the impact you believe is possible, and any logs, screenshots, or proof-of-concept material that helps us validate it. Tell us how you would like to be credited, or that you prefer not to be named.
Minimize access to data, stop if you encounter customer or personal data, and do not disrupt the service. This reporting channel is not authorization to test Xora, its customers, or third-party systems.