Security
Security & Vulnerability Disclosure
How to report a security issue to Drazill, what is in scope, how fast we respond, and the safe-harbor terms for good-faith research.
Report a vulnerability
Send suspected vulnerabilities to security@drazill.com.
The policy below is reproduced exactly as it is maintained in SECURITY.md in the Drazill repository. It is the same policy — this page adds nothing to it.
Machine-readable policy (security.txt)Reporting A Vulnerability
Report suspected vulnerabilities to security@drazill.com. Do not open public GitHub issues for security findings.
Include a clear description, affected components, reproduction steps, impact, and any supporting logs or screenshots with secrets and personal data redacted.
Scope
In scope:
- Drazill backend, frontend, SDKs, deployment workflows, and infrastructure-as-code in this repository.
- Authentication, authorization, wallet, trading, market-resolution, privacy, data-protection, and operational security issues.
- Secret exposure in tracked files, build logs, or deploy workflows.
Out of scope:
- Denial-of-service testing, spam, social engineering, phishing, or physical attacks.
- Accessing, modifying, or exfiltrating another user's data.
- Automated high-volume scans against production without written approval.
- Issues in third-party services unless they expose Drazill data or credentials.
Supported Versions
Only the current `main` branch and the currently deployed production release are supported for security fixes before public launch.
Response Targets
- Acknowledgement: within 2 business days.
- Initial triage: within 5 business days.
- Critical launch-blocking issues: remediation plan within 2 business days after triage.
- Coordinated disclosure timing is agreed case by case after a fix is available.
Safe Harbor
We will not pursue legal action for good-faith research that follows this policy, avoids privacy harm, does not degrade service, and gives Drazill a reasonable opportunity to fix the issue before disclosure.
If testing may affect production availability, money movement, user data, or third-party provider quotas, request written authorization first.