500+ manufacturers on AI, downtime, and what’s getting in the way.

Augury Coordinated Vulnerability Disclosure

Last updated: September 2026

Augury prioritizes the security of our predictive maintenance platform and values the contributions of the independent security research community. This framework outlines our coordinated vulnerability disclosure process, ensuring secure reporting channels and remediation workflows aligned with the EU Cyber Resilience Act, IEC 62443, and ISO/IEC 29147/30111 standards. 

Safe Harbor Agreement

We formally authorize good-faith security testing that complies with these guidelines. Augury commits to not pursuing civil action or initiating law enforcement referrals against researchers operating within this policy’s scope. Standard terms of service restrictions conflicting with these authorized research activities are explicitly waived for the purpose of vulnerability discovery. 

Scope of Testing

In-Scope Assets

  • Cloud Platform: Production web interfaces, REST APIs, and client-facing analytical dashboards. 
  • Edge Connectivity Gateways: Hardware gateway devices, base OS builds, communication stacks, and device-management software. 
  • IoT Sensors: Hardware endpoints, embedded firmware binaries, and wireless transmission protocols. 
  • Mobile Applications: Official Augury applications distributed through official app stores. 

Out-of-Scope Targets and Methods

  • Denial of Service (DoS/DDoS): Any activity that degrades, disables, or overwhelms Augury’s cloud APIs, backend infrastructure, or network bandwidth. 
  • Physical Plant Interruptions: Any activity that impacts physical industrial machinery, manufacturing operations, or client plant infrastructure monitored by Augury equipment. 
  • Data Privacy Violations: Accessing, exfiltrating, modifying, or deleting data belonging to Augury clients or third parties. If customer personally identifiable information (PII) or telemetry is encountered, testing must halt immediately. 
  • Social Engineering & Physical Security: Spear-phishing employees, social engineering, or unauthorized physical site intrusion. 
  • Third-Party Services: Infrastructure or applications managed by third-party providers not directly owned by Augury. 

How to Report a Vulnerability

Submit vulnerability reports and security-related incidents directly to our Product Security Incident Response Team (PSIRT) via email at security@augury.com

For automated discovery tools and standardized technical parameters, reference our RFC 9116 implementation file at https://www.augury.com/.well-known/security.txt. Submissions containing sensitive exploit data should be encrypted using our official PGP public key, which is linked directly within the security.txt file. 

Submission Requirements

To facilitate rapid triage, all submissions must include:

  • A detailed technical explanation of the vulnerability, its potential impact, and the specific asset affected. 
  • Step-by-step reproduction instructions or a functional proof-of-concept (PoC) script. 
  • Explicit exploitability conditions (e.g., required privileges, network positioning, or environment configurations). 
  • A designated email address or secure PGP public key for encrypted follow-up communication. 

What to Expect

Recognition: Once a mitigation is available, Augury will transparently publish a security advisory detailing the CVE identifier, necessary remediation steps for operators, and technical credit recognizing your contribution. 

Acknowledgment: Our PSIRT will acknowledge receipt of your disclosure within 48 hours. 

Updates: You will receive status updates every 14 calendar days until the issue is fully mitigated. 

Confidentiality: Researchers must maintain strict confidentiality and refrain from public disclosure until Augury has developed, tested, and deployed a validated patch across the active asset base.