Azul Return home

Disclosure

Security

Azul takes software integrity and security research seriously and welcomes responsible disclosure of qualifying vulnerabilities.

Responsible research

Researchers may privately report security vulnerabilities, memory-safety issues, authentication weaknesses, infrastructure bugs, and software-integrity flaws that directly affect systems controlled by Azul.

Research must be conducted in good faith, avoid harm, respect user privacy, and remain within the scope and limits below.

In scope

  • Security vulnerabilities in official Azul website services and web APIs.
  • Authentication, licensing, and key-system vulnerabilities.
  • Bootstrapper and software-update chain vulnerabilities.
  • Client-side binary integrity and memory-safety flaws.
  • Infrastructure security bugs in systems directly controlled by Azul.

Out of scope

  • Distributed denial-of-service attacks or other availability attacks.
  • Social engineering, phishing, threats, or harassment directed at staff, resellers, or users.
  • Spamming, flooding, or intentionally overloading API endpoints, bots, support systems, or infrastructure.
  • Testing third-party services, including Work.ink, Discord, resellers, or payment providers, without their permission.
  • Accessing, changing, retaining, or publishing user data beyond the minimum necessary to demonstrate a vulnerability.
  • Installing malware, maintaining unauthorized access, damaging systems, or disrupting users.

Reporting protocol

Report potential vulnerabilities privately through an official Azul Discord support ticket. Do not report undisclosed security details in public channels.

A useful report should include:

  • A clear description of the issue and its potential impact.
  • The affected service, endpoint, software version, or component.
  • Complete and repeatable steps to reproduce the issue.
  • Relevant screenshots, logs, request details, or proof-of-concept code where appropriate.
  • Any actions already taken and any data that may have been accessed.
  • A reliable way for Azul to contact the researcher.

Research limits

Stop testing and report the issue if research may expose personal information, access another user's account, damage data, interrupt the service, or affect users. Do not use a vulnerability for profit, persistence, surveillance, unauthorized access, extortion, or distribution to others.

Collect only the minimum evidence required to explain and reproduce the issue. Delete sensitive Azul or user information obtained during research after it is no longer required for the report.

Disclosure window

Allow Azul at least 14 business days after receiving a complete report to investigate and deploy an initial correction before any public discussion or disclosure.

Complex issues may require more time. Researchers should coordinate with Azul before publishing technical details, exploit methods, or proof-of-concept material.

Safe harbor

If you research and report a vulnerability in good faith while following this policy, Azul will not pursue legal action or ban your Azul account or keys solely because of that authorized research and disclosure.

Safe harbor does not apply to activity outside this policy, unlawful conduct, privacy violations, third-party systems, service disruption, data misuse, extortion, public exploitation, or attempts to retain unauthorized access. Azul cannot authorize activity involving systems it does not control.

Public misinformation and premature disclosure

Knowingly publishing fabricated vulnerability reports, false remote-access-trojan claims, deceptive security allegations, or manipulated evidence is prohibited. Publicly releasing exploit code or technical details before following the private reporting process and disclosure window may also violate Azul policies.

Azul may correct public misinformation, restrict access, preserve evidence, submit platform or hosting reports, and pursue available legal remedies when a person knowingly distributes fabricated claims or maliciously exposes users or systems.

This section does not prohibit honest opinions, accurate reporting, or good-faith criticism. It applies to knowingly false, fabricated, malicious, or prematurely disclosed security claims and materials.

Third-party systems

Work.ink, Discord, authorized resellers, payment processors, hosting providers, and other external services maintain their own security policies. Report vulnerabilities in those systems directly to their operators unless the issue specifically concerns an Azul-controlled integration.

Contact

Submit security reports through an official Azul Discord support ticket.