Skip to content
Aurexus

Legal

Vulnerability Disclosure Policy

Vulnerability Disclosure Policy

Effective 30 July 2026 · Last updated 30 July 2026

Introduction

Aurexus Group Ltd ("Aurexus", "we", "us" or "our") takes the security of our systems, platforms and data seriously. We welcome responsible disclosure of security vulnerabilities by security researchers, clients, users and the public.

This Vulnerability Disclosure Policy ("VDP") describes:

  • Which systems are in scope
  • How to report vulnerabilities
  • What you can expect from us
  • Rules of engagement for good-faith research

This policy supplements our Information Security Policy and Acceptable Use Policy.

Our Commitment

We commit to:

  • Acknowledging reports in a timely manner
  • Investigating reported vulnerabilities with appropriate priority
  • Keeping reporters informed of progress where practicable
  • Remediating confirmed vulnerabilities proportionately
  • Not pursuing legal action against researchers who comply with this policy in good faith
  • Recognising and thanking researchers who help improve our security (with consent)

Scope

In scope

  • https://www.aurexus-group.com and subdomains under our control
  • https://www.bioaegix.com and associated BioAegix infrastructure under Aurexus control
  • Aurexus-operated APIs, applications and cloud infrastructure
  • NPTTE PharmaNG and BeatIQ environments operated directly by Aurexus

Out of scope

  • Third-party services and integrations not operated by Aurexus
  • Client-deployed instances of BioAegix or other platforms managed by client organisations (report to the deploying organisation, though you may copy us)
  • Social engineering attacks against Aurexus personnel
  • Physical security attacks against premises
  • Denial of service (DoS/DDoS) attacks
  • Spam or automated scanning that degrades service availability
  • Issues requiring physical access to devices not owned by Aurexus
  • Vulnerabilities in software not operated or maintained by Aurexus
  • Findings from automated tools without validated, reproducible impact

If you are unsure whether a system is in scope, contact us before testing.

How to Report

Email: admin@aurexus-group.com
Subject line: Security Vulnerability Report

Please encrypt sensitive reports if possible. We can provide a PGP key on request.

Include

  • Description of the vulnerability and potential impact
  • Steps to reproduce (proof of concept if available)
  • Affected URL, IP address, application or component
  • Your assessment of severity (optional)
  • Your contact details for follow-up
  • Whether you wish to be credited publicly (optional)

Do not include

  • Unnecessary personal data of third parties
  • Large volumes of extracted data — use minimal proof of concept only

Rules of Engagement

To qualify for good-faith protection under this policy, you must:

  • Make a good-faith effort to avoid privacy violations, data destruction, service degradation and disruption to users
  • Not access, modify or delete data belonging to others. If you accidentally access data beyond what is necessary to demonstrate the vulnerability, stop immediately and report it
  • Not exploit vulnerabilities beyond what is necessary to demonstrate the issue
  • Not publicly disclose the vulnerability before we have had reasonable opportunity to remediate (typically 90 days, subject to agreement)
  • Not use social engineering, phishing or physical attacks against Aurexus personnel or users
  • Comply with applicable laws

What to Expect

Stage Timeframe Action
Acknowledgement Within 5 business days Confirm receipt, assign reference
Initial assessment Within 10 business days Validate report, assign severity
Remediation Varies by severity Develop and deploy fix
Resolution notification When remediated Confirm fix, coordinate disclosure

Severity handling

  • Critical — active exploitation risk, significant data exposure: prioritised immediate response
  • High — significant vulnerability with plausible exploitation: expedited remediation
  • Medium — meaningful but limited impact: scheduled remediation
  • Low / informational — minor or theoretical issues: addressed in normal development cycles

Timeframes may vary for complex issues. We will communicate delays transparently.

Safe Harbour

If you conduct security research in accordance with this policy in good faith, Aurexus will not initiate legal action against you for unauthorised access that was necessary to demonstrate the vulnerability, to the extent permitted by law.

This safe harbour does not apply if you:

  • Violate this policy
  • Access, exfiltrate or misuse personal or client data beyond minimal proof of concept
  • Extort or threaten Aurexus
  • Conduct research outside defined scope without prior approval

Safe harbour is not a guarantee of immunity from third-party action.

Recognition

With your consent, we may acknowledge your contribution in security release notes or a hall of fame page. We do not currently operate a paid bug bounty programme but may consider recognition, swag or other tokens of appreciation at our discretion.

Client Environments

BioAegix and other platforms deployed within client organisations may be managed by those organisations. If you identify a vulnerability in a client-managed environment:

  1. Report to the deploying organisation's security contact if known
  2. Copy admin@aurexus-group.com so we can coordinate if the issue relates to Aurexus software

Do not access client production environments without authorisation from the data controller.

Prohibited Activities

The following are never authorised, even under this policy:

  • Denial of service testing
  • Testing on production healthcare systems without explicit written authorisation
  • Accessing patient or special category data
  • Ransomware, malware deployment or backdoor installation
  • Destructive testing

For authorised penetration testing of client environments, contact admin@aurexus-group.com to discuss scope and written approval.

Contact

Security reports: admin@aurexus-group.com
Subject line: Security Vulnerability Report
Post: Security, Aurexus Group Ltd, Unit A, 82 James Carter Road, Mildenhall, Bury St. Edmunds, Suffolk, England, IP28 7DE

Related Documents

Review

This policy is reviewed at least annually and updated following significant security incidents or changes to our technology landscape.

Governing law: England and Wales