Skip to content

Security: Ajayos/AOS

SECURITY.md

πŸ›‘οΈ AOS Security Policy

Security is a top priority for the AOS (Ajay O S Platform) ecosystem.

We are committed to protecting user data, system integrity, and platform reliability.


πŸ” Reporting a Vulnerability

If you discover a security vulnerability:

❌ Do NOT open a public GitHub issue
❌ Do NOT disclose the issue publicly

βœ… Report privately via email:

security@ajayos.com

Include:

  • Description of the vulnerability
  • Steps to reproduce (if applicable)
  • Affected endpoints or components
  • Impact assessment (if known)

πŸ“© Response Timeline

We aim to:

  • Acknowledge reports within 72 hours
  • Provide an initial assessment within 7 days
  • Resolve confirmed vulnerabilities as quickly as possible

Timelines may vary depending on severity and complexity.


πŸ”Ž Scope

This policy applies to:

  • Public-facing applications
  • APIs and services
  • Documentation systems
  • Official Ajayos domains
  • Public GitHub repositories under AOS

πŸ§ͺ Responsible Disclosure

We support responsible disclosure practices:

  • Please allow reasonable time for remediation
  • Avoid accessing or modifying user data
  • Avoid service disruption
  • Do not exploit the vulnerability beyond proof of concept

We appreciate responsible researchers and may acknowledge valid reports.


🚫 Out of Scope

The following are generally not considered security issues:

  • Missing security headers without exploit
  • Rate limiting suggestions without abuse demonstration
  • Self-XSS
  • Clickjacking on non-sensitive pages
  • Theoretical vulnerabilities without proof

πŸ”’ Security Practices (High-Level)

While internal implementations remain private, AOS follows best practices including:

  • Secure authentication mechanisms
  • Controlled API access
  • Regular dependency updates
  • Environment isolation
  • Monitoring and logging
  • Backup and recovery planning

πŸ“’ Legal Safe Harbor

We will not pursue legal action against researchers who:

  • Follow responsible disclosure
  • Avoid privacy violations
  • Act in good faith

Thank you for helping keep AOS secure.

There aren’t any published security advisories