Vulnerability Disclosure Policy
Effective Date: July 10, 2026 | Last Updated: July 10, 2026
At Crux AI Technologies, the security of our users' data is our highest priority. We appreciate the work of security researchers in keeping the digital ecosystem safe. If you believe you have discovered a security vulnerability or data exposure risk in our application, please report it to us responsibly according to this policy.
How to Report a Vulnerability
Please submit all security vulnerability reports directly to our security team via email at:
Security Reports
security@cruxapp.aiTo help us triage and resolve the issue quickly, please include the following details in your report:
- A clear description of the vulnerability and its potential impact.
- Detailed step-by-step instructions (or a proof-of-concept script/screenshot) to replicate the issue.
- The specific endpoints, URLs, or parameters affected.
- Your contact information so we can follow up if we need additional details.
Scope
The following assets are in scope for responsible security research:
- The Crux mobile application (iOS and Android).
- Crux web services and API endpoints.
- Authentication and authorization mechanisms.
- Data storage, transmission, and processing pipelines.
Our Commitment to You
If you act in good faith and follow this policy, we commit to the following:
Timely Response
We will acknowledge receipt of your report within 48 business hours.
Remediation
We will work diligently to validate, patch, and fix verified vulnerabilities as quickly as possible.
Safe Harbor
We will not pursue legal action against researchers who discover vulnerabilities accidentally and report them to us without exploiting them or disclosing them publicly before a patch is issued.
Good-Faith Collaboration
We will keep you informed of our progress in resolving the issue and will credit you (if desired) once the vulnerability has been patched.
Prohibited Actions
While we welcome security research, the following actions are strictly prohibited:
Accessing, modifying, destroying, or downloading data belonging to other users.
Executing Denial of Service (DoS) or Distributed Denial of Service (DDoS) attacks.
Using automated scanners that generate high volumes of disruptive traffic.
Social engineering, phishing, or physical security attacks against our team or infrastructure.
Public disclosure of a vulnerability before we have had reasonable time to address it.
Contact
For all security-related inquiries, please contact us at:
Crux AI Technologies — Security Team
Email: security@cruxapp.ai
Thank you for helping us keep Crux safe and secure for everyone.