Trust statement
syrarchity® exists to protect. The same discipline we apply to the Cyber Realm and the Physis Realm of Aurora governs how we operate this website and how we engage with the security community.
Our work follows established principles — least privilege, defense in depth, separation of duties, and verification over assumption. We do not publish architectural detail about the systems and entities under our protection; discretion is part of the mandate.
Coordinated disclosure
We value the work of good-faith security researchers. If you believe you have found a vulnerability in this website or in any system operated under the syrarchity mandate, we ask you to report it to us privately before any public disclosure.
How to report
E-mail: security@syrarchity.com
PGP key: to be published at /pgp-key.txt — until then, request it by e-mail.
Machine-readable policy: /.well-known/security.txt (RFC 9116)
Please include: a description of the issue, steps to reproduce, the affected URL or system, and — if you wish — a name or handle for acknowledgement.
What we commit to
- Acknowledgement of your report within 72 hours.
- A substantive assessment and expected timeline within 7 days.
- Remediation prioritised by severity, and notice to you when the issue is resolved.
- No legal action against researchers who act in good faith within the rules below.
Rules of engagement
- Do not access, modify, or exfiltrate data that is not your own; use test data wherever possible.
- No denial-of-service, social engineering, physical intrusion, or spam.
- Stop and report immediately once a vulnerability is confirmed — do not pivot further.
- Keep the issue confidential until we confirm remediation, or until 90 days have passed, whichever comes first.
Scope
In scope: syrarchity.com and subdomains. Systems of Aurora and related entities are covered only where we explicitly confirm scope with you after your first message. When in doubt — ask first, test second.