Skip to content
Drazill logoStagingTesting mode — staging environment. No real money: balances, trades, and accounts are for testing only and may be reset at any time.DEMODemo mode: simulated data, for showcase only
Security

Security & Vulnerability Disclosure

How to report a security issue to Drazill, what is in scope, how fast we respond, and the safe-harbor terms for good-faith research.

Report a vulnerability

Send suspected vulnerabilities to security@drazill.com.

The policy below is reproduced exactly as it is maintained in SECURITY.md in the Drazill repository. It is the same policy — this page adds nothing to it.

Machine-readable policy (security.txt)

Table of contents

Reporting A VulnerabilityScopeSupported VersionsResponse TargetsSafe Harbor

Reporting A Vulnerability

Report suspected vulnerabilities to security@drazill.com. Do not open public GitHub issues for security findings. Include a clear description, affected components, reproduction steps, impact, and any supporting logs or screenshots with secrets and personal data redacted.

Scope

In scope: - Drazill backend, frontend, SDKs, deployment workflows, and infrastructure-as-code in this repository. - Authentication, authorization, wallet, trading, market-resolution, privacy, data-protection, and operational security issues. - Secret exposure in tracked files, build logs, or deploy workflows. Out of scope: - Denial-of-service testing, spam, social engineering, phishing, or physical attacks. - Accessing, modifying, or exfiltrating another user's data. - Automated high-volume scans against production without written approval. - Issues in third-party services unless they expose Drazill data or credentials.

Supported Versions

Only the current `main` branch and the currently deployed production release are supported for security fixes before public launch.

Response Targets

- Acknowledgement: within 2 business days. - Initial triage: within 5 business days. - Critical launch-blocking issues: remediation plan within 2 business days after triage. - Coordinated disclosure timing is agreed case by case after a fix is available.

Safe Harbor

We will not pursue legal action for good-faith research that follows this policy, avoids privacy harm, does not degrade service, and gives Drazill a reasonable opportunity to fix the issue before disclosure. If testing may affect production availability, money movement, user data, or third-party provider quotas, request written authorization first.

Read more

Trust & Safety

How your money and data are protected.

Privacy Policy

What we collect and how we use it.

System status

Live platform status and incident history.

Markets
Portfolio