Aragorn HomeVulnerability Disclosure Policy
Effective Date: January 5, 2026

Vulnerability Disclosure Policy

Introduction

Aragorn moves employee data between HR systems. We take the security of that data seriously, and we know that internal testing does not catch everything. If you have found a security vulnerability in something we run, we want to hear about it.

This policy explains what you may test, how to tell us what you find, and what we commit to in return.

What is in scope

This policy covers the Aragorn public website at www.aragorn.ai, including its subpages.

What is out of scope

Everything else. In particular:

The Aragorn application, our APIs, and customer environments. These hold employee records belonging to our customers. They are not open for unsolicited testing. If you believe you have found a vulnerability that affects them, write to us and describe it rather than testing it, and we will investigate and come back to you. We would rather hear a well-reasoned hypothesis than have someone confirm it against real data.

Services operated by third parties. Our website uses hosted services for content management, forms, scheduling and analytics. Vulnerabilities in those products belong to the vendors who build them. Please report them through the vendor's own disclosure process, not to us. We are happy to hear about a misconfiguration on our side of one of those services.

Systems belonging to our customers or partners, including any HR system we connect to on a customer's behalf.

People and places. Our staff, our offices, and our corporate IT.

How to report

Email security@aragorn.ai.

A report we can act on usually includes:

  • Where you found it. The URL, endpoint or page.
  • What kind of issue it is.
  • Steps to reproduce it, in enough detail that we can follow them.
  • What someone could actually do with it.
  • Any supporting output, screenshots or proof-of-concept code.

Please send one issue per email. If you are not sure whether something counts, send it anyway and say what you are unsure about.

What we commit to

  • We will acknowledge your report within five business days.
  • We will tell you what we have decided and roughly when we expect to fix it, and we will let you know when it is fixed.
  • If you would like to be credited publicly once the issue is resolved, tell us and we will. If you would rather stay anonymous, that is fine too.
  • We will not take legal action against you for research carried out in good faith under this policy.

Safe harbour

If you make a good faith effort to follow this policy while researching and reporting a vulnerability, we will treat your research as authorised. We will work with you to understand and resolve the issue quickly, and Aragorn will not initiate or recommend legal action against you in connection with that research.

If a third party brings legal action against you for research you carried out in good faith under this policy, we will make it known that your research was authorised.

This safe harbour does not extend to research that falls outside this policy, and we cannot waive the rights of any third party.

Rules

By taking part you agree to all of the following.

  • Do not access, modify, delete or download data that is not yours. If you come across customer data, employee records, or anyone's personal information, stop immediately, do not save a copy, and tell us what you saw in your report.
  • Stop once you have confirmed an issue. Establishing that a vulnerability exists is enough. Do not pivot to other systems, escalate privileges, or see how far it goes.
  • Do not degrade the service. No denial of service, no volumetric or load testing, no automated scanning heavy enough to affect other users.
  • Do not use social engineering, phishing, or physical attacks against our staff, our customers, or anyone else.
  • Do not submit spam or automated test submissions through forms on our site.
  • Give us time before you publish. Please do not disclose the issue publicly until we have fixed it, or until 90 days have passed since your report, whichever comes first. If you need to move faster than that, talk to us and we will work something out.
  • Follow the law. This policy does not authorise anything illegal in your jurisdiction or ours.

If you break these rules, the safe harbour above does not apply.

Findings we do not usually act on

These come up often and, without a working exploit that shows real impact, we will acknowledge them and close them. If you can demonstrate genuine impact, we want to see it, so tell us what the impact is rather than just naming the finding.

  • Missing or misconfigured security headers, with no demonstrated exploit
  • SPF, DKIM or DMARC configuration, without a working spoofed message
  • Missing cookie flags on cookies that carry nothing sensitive
  • Self-XSS, or issues that need the victim to paste code into their own console
  • Clickjacking on pages with no sensitive action
  • Missing rate limiting on unauthenticated endpoints, absent a demonstrated attack
  • Raw output from an automated scanner, with no evidence the finding is exploitable
  • Software version disclosure and banner grabbing
  • Issues requiring physical access to a device, a rooted or jailbroken device, or an already compromised browser
  • Vulnerabilities in third-party software or services we do not operate
  • Best-practice recommendations with no demonstrated security impact
  • Publicly accessible content that is meant to be public

Rewards

Aragorn does not currently run a paid bug bounty programme, and we do not offer money for vulnerability reports. We do offer credit, a quick and honest response, and a direct line to the people who will fix the issue.

If that changes, we will say so here.

Changes to this policy

We may update this policy. The effective date at the top of the page tells you when it last changed.