Report vulnerabilities privately. Do not open a public issue for a suspected security defect.
- On the affected repository, open Security → Advisories → New draft security advisory (GitHub private reporting).
- If that tab is not enabled, email the AISI Dev Co director via the contact on Companies House for AISI DEV CO. LTD (16819822) and put
SECURITYin the subject.
Include the repo name, Acumatica version, a reproduction, and whether tenant data is at risk.
- We will not accept reports that require us to run untrusted exploit payloads against systems we do not own.
- Licensed Acumatica
PX.*assemblies will not be published, even to “help debug.”
Public AISI repositories and the customization zips / NuGet packages they ship. Client private repositories are out of scope for this document.