Vulnerability disclosure policy
How to report a security vulnerability in a Dazr product, and what you can expect from us. Last updated 6 October 2026.
Reporting a vulnerability
If you find a security vulnerability in one of our services, please report it to security@dazr.eu. Describe what you found and the steps to reproduce it, and name the address or app version concerned.
- Scope. The Dazr websites and services on dazr.eu and its subdomains, their APIs, Dazr Browser and the Dazr Suite apps.
- Out of scope. Services run by our providers, which have their own programmes; reports about missing best practices without a way to exploit them; and scanner output without a demonstrated impact.
- Testing with care. Use your own accounts and test data, access other people’s data only as far as needed to show the problem, and keep the service running for everyone: no denial-of-service tests, spam or social engineering.
- Safe harbour. If you act in good faith and follow this policy, we consider your research authorised and will not take legal action against you. Please give us reasonable time to fix the problem before you share details publicly.
- Our response. We acknowledge your report within 5 working days and keep you informed until the problem is fixed.
- Publication. Once the problem is fixed, we agree with you when the details can be published, and we name you if you wish. We do not run a paid bug bounty programme.
Our security contact is also published in security.txt (RFC 9116).