Responsible disclosure

Found something?
Tell us properly.

Draxion works with the security research community to identify and resolve vulnerabilities. This policy sets out what we expect from you, and — just as importantly — what you get from us in return.

Submit a report
security@draxion.io
Acknowledged
Within 2 business days
Assessed
Within 10 business days
Encryption
PGP key on request
Updated
May 31, 2025

Our side of the deal

What we commit to, in writing.

Report a vulnerability in good faith under this policy and every one of these applies to you.

Acknowledge receipt of your report within 2 business days.

Provide a substantive response within 10 business days, including our initial assessment, severity classification and proposed remediation timeline.

Keep you informed of our progress at reasonable intervals until the vulnerability is resolved.

Notify you when the vulnerability has been fully remediated.

Not pursue civil or criminal legal action against researchers who act in good faith and comply with this policy.

Credit you in our security acknowledgments if you wish, and with your explicit permission.

Treat your report as confidential. We will not share your identity or report details with third parties without your consent, except where required by law.

Scope

Where to look, and where not to.

Testing outside the in-scope list is not covered by safe harbor, so please check this before you start.

In scope

draxion.io and all subdomains (app.draxion.io, api.draxion.io and others)

The Draxion web application and platform dashboard

The Draxion REST API (v1)

The Draxion Chrome extension (Chrome Web Store ID on file)

Draxion mobile applications when released

Out of scope

Third-party services and infrastructure used by Draxion (Vercel, Supabase, Clerk, Arcjet) — report these directly to the respective vendors.

Social engineering attacks against Draxion employees, contractors or customers.

Physical security of any Draxion facilities or personnel.

Volumetric denial of service (DoS) or distributed denial of service (DDoS) attacks.

Automated scanning that generates excessive load on production systems or degrades service for other customers.

Vulnerabilities in browser extensions other than the Draxion extension.

Vulnerabilities requiring physical access to a user’s unlocked device.

Reports from automated scanners without manual verification of exploitability.

Priority classes

What we most want to hear about.

Listed highest to lowest priority. A finding in P1 will get our full attention the day it lands.

P1

Cross-organization data access

Any vulnerability that allows one Draxion customer to read, write or infer data belonging to another customer. This is our highest priority class, given the sensitivity of AI governance data.

P2

Authentication bypass or privilege escalation

Any vulnerability allowing access to authenticated functionality without valid credentials, or elevation from Member to Admin or Owner role without authorization.

P3

Injection vulnerabilities

SQL injection, prompt injection against LLM components, command injection, cross-site scripting or server-side template injection.

P4

Insecure direct object references

Accessing another user’s or organization’s resources by manipulating object identifiers in API requests.

P5

Sensitive data exposure

API responses returning personal data, credentials or internal configuration beyond what is required for the requested operation.

P6

Audit log integrity

Any vulnerability allowing modification or deletion of audit log entries, or bypassing the cryptographic signing that protects log integrity.

P7

Browser extension vulnerabilities

Content script injection, cross-origin data leakage, or unauthorized access to extension storage or messaging.

Rules of engagement

Comply with all eight, and safe harbor applies.

These are conditions, not suggestions. Safe harbor covers researchers who meet every one of them.

While you test

Make a good faith effort to avoid privacy violations, data destruction, service degradation and interruption of service to other users at all times.

Only access, modify or exfiltrate data from accounts you own, or accounts for which you have received explicit written permission from the account owner to test.

Do not exfiltrate, modify, delete or corrupt any data beyond the minimum necessary to demonstrate the existence of the vulnerability.

Do not access, download or exfiltrate any personal data belonging to Draxion customers or their employees. If you accidentally access such data, stop immediately and report it.

Do not disclose vulnerability details to any third party until Draxion has had a reasonable opportunity to investigate and remediate — typically 90 days from acknowledgement, or as mutually agreed.

Do not conduct testing against production accounts belonging to real Draxion customers without their explicit written consent.

Do not use findings for any purpose other than reporting them to Draxion under this policy.

Provide sufficient technical detail for Draxion to reproduce and verify the vulnerability before requesting remediation confirmation.

What to put in the report

A high quality report helps us triage and remediate faster.

A clear description of the vulnerability and its potential impact if exploited.

Step-by-step reproduction instructions, specific enough that a Draxion engineer who did not discover the issue can reproduce it independently.

The URL, endpoint, parameter, header or component affected.

Screenshots, screen recordings, HTTP request/response captures or proof-of-concept code, where it is safe to include them.

Your assessment of severity using the CVSS scale if possible: Critical / High / Medium / Low.

Any conditions required to reproduce the issue — authenticated versus unauthenticated, specific browser, specific account type.

Your contact details and preferred method of communication.

Coordinated disclosure

From submission to publication.

Our default track. Every step has a date attached so you always know where a report stands.

Day 0

You submit

Researcher submits the report to security@draxion.io.

Day 1–2

We acknowledge

Draxion acknowledges receipt and assigns a tracking reference.

Day 1–10

We assess

Draxion provides an initial assessment including severity, affected components and remediation timeline.

Day 10–90

We remediate

Draxion works to remediate, with progress updates at least every 30 days. Critical vulnerabilities are prioritized for remediation within 30 days where technically feasible.

Day 90

Disclosure deadline

Default disclosure deadline. If remediation is not complete by day 90 we will discuss an extension with the researcher. We will not request extensions beyond 120 days except in exceptional circumstances.

After the fix

We close the loop

Draxion notifies the researcher of remediation and agrees the public disclosure format and timing.

Safe harbor

Research under this policy is authorized research.

Draxion considers security research conducted in accordance with this policy to be:

  • Authorized access under the Computer Fraud and Abuse Act (CFAA) and equivalent laws in other jurisdictions, including the Computer Misuse Act 1990 (UK) and similar national legislation.
  • Exempt from DMCA Section 1201 anti-circumvention provisions where access is necessary to conduct good-faith security research.
  • Conducted in good faith and therefore not subject to civil or criminal legal action by Draxion.

If legal action is initiated by any third party against a researcher who has fully complied with this policy, Draxion will take reasonable steps to make known to the relevant authority that the research was conducted in accordance with it.

Safe harbor applies only where the researcher has complied with every rule of engagement above. Researchers who violate those requirements are not covered.

Contact

Send it to the security team.

PGP encryption is available for sensitive reports — request our public key at the address below and we will respond with it within one business day.

For general security questions that are not vulnerability reports, see the security page.