What your report should include
- Affected surface, URL, app version and device
- Steps to reproduce and the expected behaviour
- Possible impact and any protective measures already taken
- Only the minimum necessary anonymised evidence
Please do not
- Use social engineering, phishing or attacks against employees
- Cause disruption, run load tests or send automated requests at scale without approval
- Access, change or publish anyone else’s data
- Make demands under threat of publication
What should be visible afterwards
A report should have a traceable receipt, a tightly bounded reproduction and an assessment of the affected data and functions. We currently promise neither a fixed response time nor a reward; both would require a reviewed process and a published programme.
Until a dedicated security contact is published and secured, use support@audeciusofficial.com with the subject “Security Report”. Do not send active secrets or personal data without encryption.
Machine-readable contact: security.txt

