1How to report
Email security@awmza.com with a clear description of the issue, the steps to reproduce it, the affected URL or endpoint, and any evidence (screenshots, request/response logs). Encrypted email is welcome but not required — do not include live exploit code that could cause damage if intercepted.
You may also see /.well-known/security.txt for the same contact in machine-readable form.
2Scope
In scope:
- security.awmza.com and its subpaths (dashboard, account, oidc, API)
- Authentication, session, tenant-isolation, and payment-webhook logic
- The public passive-scan API
Out of scope:
- Denial-of-service, volumetric, or spam testing
- Social engineering or phishing against AWMZA staff or customers
- Physical access attempts, or attacks against Hetzner's own infrastructure
- Automated scanning that generates high-volume traffic without prior agreement
- Testing any account, domain, or tenant that is not your own
- Findings that only affect out-of-date or unsupported browsers
3Safe harbor
If you make a good-faith effort to follow this policy while researching a vulnerability, we will not pursue legal action against you for that research. This applies only to testing that stays within the scope above and does not access, modify, or exfiltrate other customers' data.
4What to expect from us
- Acknowledgement of your report within 3 business days
- An honest assessment of severity and whether it is a confirmed issue
- A fix timeline appropriate to severity — critical issues are prioritized immediately
- Credit in this page's acknowledgements section, if you would like it
5Acknowledgements
No external researcher has reported a confirmed vulnerability here yet. The first verified report earns the first name on this list.
Contact
security@awmza.com · PGP not yet published Follow-up