Last updated: September 2026
Augury prioritizes the security of our predictive maintenance platform and values the contributions of the independent security research community. This framework outlines our coordinated vulnerability disclosure process, ensuring secure reporting channels and remediation workflows aligned with the EU Cyber Resilience Act, IEC 62443, and ISO/IEC 29147/30111 standards.
Safe Harbor Agreement
We formally authorize good-faith security testing that complies with these guidelines. Augury commits to not pursuing civil action or initiating law enforcement referrals against researchers operating within this policy’s scope. Standard terms of service restrictions conflicting with these authorized research activities are explicitly waived for the purpose of vulnerability discovery.
Scope of Testing
In-Scope Assets
Out-of-Scope Targets and Methods
How to Report a Vulnerability
Submit vulnerability reports and security-related incidents directly to our Product Security Incident Response Team (PSIRT) via email at security@augury.com.
For automated discovery tools and standardized technical parameters, reference our RFC 9116 implementation file at https://www.augury.com/.well-known/security.txt. Submissions containing sensitive exploit data should be encrypted using our official PGP public key, which is linked directly within the security.txt file.
Submission Requirements
To facilitate rapid triage, all submissions must include:
What to Expect
Recognition: Once a mitigation is available, Augury will transparently publish a security advisory detailing the CVE identifier, necessary remediation steps for operators, and technical credit recognizing your contribution.
Acknowledgment: Our PSIRT will acknowledge receipt of your disclosure within 48 hours.
Updates: You will receive status updates every 14 calendar days until the issue is fully mitigated.
Confidentiality: Researchers must maintain strict confidentiality and refrain from public disclosure until Augury has developed, tested, and deployed a validated patch across the active asset base.