Trust

Security Disclosure

If you have found a vulnerability, we want to hear about it and we will not threaten you for telling us. Here is how to report it and what happens next.

Last updated 30 July 2026 Applies to everyone using azi.solutions

How to report

Email [email protected] with “security” in the subject line. Include:

  • The affected URL or endpoint.
  • What the issue is, and the steps to reproduce it.
  • What an attacker could actually do with it.
  • Anything you need from us to demonstrate it.

Encrypted email is fine if you prefer — ask and we will arrange it.

What we promise

You get…When
Acknowledgement that a person has read itWithin one business day
An assessment of whether we agree it is a vulnerabilityWithin three business days
A fix, or a date and a reason if it will take longerDepends on severity, told to you honestly
Credit on this page, if you want itWhen the fix ships

We will not take legal action against you for good-faith research that follows the rules below, and we will not ask you to sign anything before we will listen.

Rules and scope

In scope: azi.solutions, its API, and anything running on our own infrastructure.

  • Do not access, modify or delete data that is not yours. If you can prove the issue with your own test account, do that.
  • Do not run denial-of-service or volumetric tests. The rate limits are published; do not try to break them.
  • Do not social-engineer us or anyone else.
  • Give us a reasonable chance to fix it before publishing.

Out of scope: client sites we built but do not host or maintain (report those to the client, and tell us so we can help), third-party platform issues, missing headers with no demonstrable impact, and automated scanner output with no working proof.

Known and accepted

A few things are deliberate rather than oversights:

  • The API fetches public URLs by design. Private and reserved IP ranges are refused at every redirect hop; if you find a way past that, it is a real finding and we want it.
  • The free tools run entirely in the browser. There is no upload endpoint to attack because files never leave your device.
  • We have no bug bounty budget. We cannot pay, and we would rather say so than imply otherwise. Credit and a genuine thank-you is what we have.

Credits

Nobody has reported a vulnerability yet. When someone does and wants naming, they will be listed here.