ĀRU Intelligence welcomes responsible reports that help protect users and research artifacts.
Please do not open a public issue for a suspected vulnerability. Email office@aruintelligence.com with:
- The affected repository and file, release, or commit
- A concise description of the issue and potential impact
- Reproduction steps or a proof of concept
- Any suggested mitigation
- A safe way to contact you
Use the subject line: Security report — repository name.
Most public ĀRU repositories are experimental research prototypes, not production services. Reports involving credential exposure, unsafe code execution, dependency compromise, injection, privacy loss, or a misleading security boundary are especially useful.
Please avoid privacy violations, destructive testing, service disruption, social engineering, and accessing data that is not yours. Allow reasonable time for investigation and remediation before public disclosure.
We will acknowledge a complete report when practicable, investigate in good faith, and credit reporters who want attribution. This policy does not create a bug-bounty program or promise payment.