How to report
- Email clancaster@lancastersolutionsllc.com with subject Asuruas Security Report.
- Describe the affected URL, component, account context, and behavior.
- Provide reproducible steps and minimum evidence.
- Include your preferred contact method and attribution preference.
Research expectations
- Avoid privacy violations, persistence, social engineering, denial of service, and destruction.
- Do not access or retain data beyond what is necessary.
- Stop and report immediately if sensitive information is exposed.
- Allow reasonable time before public disclosure.
Operational implementation
- Assign an owner for implementing and reviewing the obligations described in Responsible Disclosure.
- Map the policy to product settings, contracts, support procedures, data flows, records, and staff responsibilities.
- Keep the public language aligned with actual production behaviour and contracted commitments.
- Retain approval, effective-date, change-history, and customer-notice records.
Review triggers
- A material product, pricing, data-processing, security, vendor, or support change.
- A new jurisdiction, customer class, contract requirement, or regulatory obligation.
- An incident, complaint, audit finding, or operational exception that shows the published process is incomplete.
- A change that could create testing outside the approved scope or at an unsafe rate.
Decision and verification record
Scope
Name the website, environment, URLs, entities, templates, or user journeys included in the responsible disclosure decision.
Decision
Record the chosen action, owner, priority, dependencies, approval, and the evidence that justified it.
Verification
Repeat the relevant check from an authorized context, confirm the original evidence is no longer reproducible, and retain a dated result.
Turn responsible disclosure into an accountable record.
An implementation checklist showing where Responsible Disclosure is reflected in product behaviour and business procedure.