1. Reporting
- Email clancaster@lancastersolutionsllc.com with subject 'Asuruas Security Report'.
- Describe the affected URL or component, account context, impact, reproducible steps, and minimum supporting evidence.
- Include your preferred contact method and whether you want attribution. Do not send live credentials, private keys, or unnecessary personal information.
2. In-scope research
Good-faith research is limited to Asuruas systems and accounts that you own or are expressly authorized to use. Customer websites, other tenants, providers, staff accounts, and third-party systems are out of scope unless their owner separately authorizes the activity.
3. Prohibited methods
- Denial of service, stress testing, destructive testing, malware, persistence, social engineering, phishing, physical attacks, or credential attacks.
- Accessing, modifying, deleting, or retaining another person's data; expanding scope after unexpected access; or testing in a way likely to impair service.
- Public disclosure before we have had a reasonable opportunity to investigate, mitigate, and coordinate a release.
4. If data is exposed
Stop immediately, do not continue searching, do not download more data, preserve only the minimum evidence needed to report the issue, and delete retained data after we confirm receipt or sooner if requested and legally permitted.
5. Our response
We will acknowledge reports as soon as reasonably practicable, validate and prioritize them according to risk, request clarification when needed, and coordinate remediation and disclosure when appropriate. We do not promise a bounty, payment, public credit, or a specific remediation date unless agreed in writing.
6. Good-faith assurance
Lancaster Solutions LLC will not initiate legal action solely because of accidental, good-faith research that stays within this policy, avoids privacy and service harm, and is reported promptly. This assurance does not bind third parties, excuse violations of law or contract, authorize continued access after a stop request, or apply to extortion, threats, deception, or misuse of data.
7. Date
Effective August 9, 2026.