Security Disclosure
If you have found a vulnerability, we want to hear about it and we will not threaten you for telling us. Here is how to report it and what happens next.
How to report
Email [email protected] with “security” in the subject line. Include:
- The affected URL or endpoint.
- What the issue is, and the steps to reproduce it.
- What an attacker could actually do with it.
- Anything you need from us to demonstrate it.
Encrypted email is fine if you prefer — ask and we will arrange it.
What we promise
| You get… | When |
|---|---|
| Acknowledgement that a person has read it | Within one business day |
| An assessment of whether we agree it is a vulnerability | Within three business days |
| A fix, or a date and a reason if it will take longer | Depends on severity, told to you honestly |
| Credit on this page, if you want it | When the fix ships |
We will not take legal action against you for good-faith research that follows the rules below, and we will not ask you to sign anything before we will listen.
Rules and scope
In scope: azi.solutions, its API, and anything running on our own infrastructure.
- Do not access, modify or delete data that is not yours. If you can prove the issue with your own test account, do that.
- Do not run denial-of-service or volumetric tests. The rate limits are published; do not try to break them.
- Do not social-engineer us or anyone else.
- Give us a reasonable chance to fix it before publishing.
Out of scope: client sites we built but do not host or maintain (report those to the client, and tell us so we can help), third-party platform issues, missing headers with no demonstrable impact, and automated scanner output with no working proof.
Known and accepted
A few things are deliberate rather than oversights:
- The API fetches public URLs by design. Private and reserved IP ranges are refused at every redirect hop; if you find a way past that, it is a real finding and we want it.
- The free tools run entirely in the browser. There is no upload endpoint to attack because files never leave your device.
- We have no bug bounty budget. We cannot pay, and we would rather say so than imply otherwise. Credit and a genuine thank-you is what we have.
Credits
Nobody has reported a vulnerability yet. When someone does and wants naming, they will be listed here.
