Draft for review. This page was written to match how the site works, but it hasn't been checked by a lawyer yet.
We take the security of azed.ai seriously. If you believe you've found a vulnerability, we'd like to hear from you, and we'll work with you to fix it.
Reporting a vulnerability
Email hello@azed.ai with “Security report” in the subject. Please include:
- the page or endpoint affected;
- steps to reproduce the issue, and what you expected to happen; and
- how we can reach you for follow-up questions.
We'll acknowledge your report within two working days and keep you updated while we investigate.
Please test responsibly
- Don't access, change or delete data that isn't yours, and stop as soon as you've confirmed an issue.
- Don't run denial-of-service, load or spam tests, including against the contact form, newsletter or demo.
- Don't use social engineering or physical attacks.
- Give us reasonable time to fix the issue before telling anyone else about it.
We won't take legal action against good-faith research that follows these guidelines. We don't run a paid bug bounty, but we're glad to credit you if you'd like.
How we protect the site
- Pages are static files served only over HTTPS, with security headers including a content security policy.
- API keys and passwords stay on the server and are never sent to the browser.
- Forms and the demo are protected by Cloudflare Turnstile, input validation and rate limits.
- The web server stores no enquiries or sign-ups; they're delivered by email.
Our machine-readable contact details are in security.txt.