Responsible Disclosure

Found a security issue? Tell us.

We treat every good-faith report seriously. This page explains what is in scope, how to report safely, and what you can expect from us in return.

Last updated: 8 September 2026

1How to report

Email security@awmza.com with a clear description of the issue, the steps to reproduce it, the affected URL or endpoint, and any evidence (screenshots, request/response logs). Encrypted email is welcome but not required — do not include live exploit code that could cause damage if intercepted.

You may also see /.well-known/security.txt for the same contact in machine-readable form.

2Scope

In scope:

  • security.awmza.com and its subpaths (dashboard, account, oidc, API)
  • Authentication, session, tenant-isolation, and payment-webhook logic
  • The public passive-scan API

Out of scope:

  • Denial-of-service, volumetric, or spam testing
  • Social engineering or phishing against AWMZA staff or customers
  • Physical access attempts, or attacks against Hetzner's own infrastructure
  • Automated scanning that generates high-volume traffic without prior agreement
  • Testing any account, domain, or tenant that is not your own
  • Findings that only affect out-of-date or unsupported browsers

3Safe harbor

If you make a good-faith effort to follow this policy while researching a vulnerability, we will not pursue legal action against you for that research. This applies only to testing that stays within the scope above and does not access, modify, or exfiltrate other customers' data.

If a test could plausibly affect another customer's account or data, stop and email us first before proceeding — we will help you test safely instead.

4What to expect from us

  • Acknowledgement of your report within 3 business days
  • An honest assessment of severity and whether it is a confirmed issue
  • A fix timeline appropriate to severity — critical issues are prioritized immediately
  • Credit in this page's acknowledgements section, if you would like it
We do not currently run a paid bug-bounty program with fixed reward amounts Follow-up — reports are reviewed and, where genuinely valuable, may be rewarded on a discretionary, case-by-case basis. We will not overstate this as a funded bounty program until it formally exists.

5Acknowledgements

No external researcher has reported a confirmed vulnerability here yet. The first verified report earns the first name on this list.

Contact

security@awmza.com · PGP not yet published Follow-up