Skip to main content
Security Research

Responsible Disclosure Program

How security researchers can report vulnerabilities to Aarozi

At Aarozi, the security of our merchants' customer data and loyalty infrastructure is paramount. We appreciate the contributions of ethical security researchers who find and report security vulnerabilities responsibly.

1. Safe Harbor Guidelines

If you act in good faith and follow these guidelines, we will not pursue legal action against you:

  • Do not view, alter, extract, or delete customer or merchant personal data belonging to others.
  • Do not perform denial-of-service (DoS/DDoS) attacks, brute force attacks, or spam automated forms.
  • Do not use social engineering, phishing, or physical attacks against Aarozi personnel or merchants.
  • Give our engineering team reasonable time (minimum 30 days) to patch any reported issue before publicly discussing it.

2. How to Submit a Report

Email your report to security@aarozi.com including:

  • Detailed reproduction steps and clear proof-of-concept (HTTP request / curl).
  • Affected URL, API endpoint, or component.
  • Potential impact and remediation suggestions.

3. Response Timeline SLA

  • Acknowledgment: Within 48 business hours.
  • Triage & Assessment: Within 5 business days.
  • Resolution & Confirmation: Timelines prioritized according to CVSS severity.