Vulnerability Disclosure Policy

J Computer Solutions LLC welcomes responsible disclosure of security vulnerabilities. This policy provides safe harbor for researchers who identify and report issues in good faith.

Safe Harbor Statement

We will not pursue legal action against researchers who discover and responsibly disclose security vulnerabilities in accordance with this policy. We consider good-faith security research to be authorized activity under the Computer Fraud and Abuse Act (CFAA) and similar laws.

1. Scope

This policy covers the following systems:

  • projectaziz.com and all subdomains;
  • The Project Aziz REST API;
  • Project Aziz mobile web application;
  • The WebSocket and WebTransport endpoints.

Out of scope: third-party services (Stripe, cloud providers), social media accounts, and physical hardware not directly managed by J Computer Solutions LLC.

2. How to Report

Submit vulnerability reports to security@projectaziz.com with the subject line "Vulnerability Disclosure." Your report should include:

  • A description of the vulnerability and its potential impact;
  • Steps to reproduce the issue;
  • Any proof-of-concept code or screenshots;
  • Your contact information for follow-up (optional).

You may also use our contact page to initiate a disclosure.

3. Response Timeline

  • Acknowledgment: Within 72 hours of receipt;
  • Initial assessment: Within 7 business days;
  • Status update: Every 14 days until resolved;
  • Resolution target: 30 days for critical issues; 90 days for lower severity.

4. Rules of Engagement

To qualify for safe harbor, researchers must:

  • Avoid accessing, modifying, or deleting data belonging to other users;
  • Not perform denial-of-service attacks or disruptive testing;
  • Not exploit vulnerabilities beyond what is necessary to demonstrate their existence;
  • Not use social engineering against Project Aziz personnel;
  • Not publicly disclose the vulnerability before we have had reasonable time to address it (minimum 90 days);
  • Comply with all applicable laws.

5. Recognition

With your permission, we will acknowledge researchers who report valid vulnerabilities in our security hall of fame. We do not currently offer monetary bug bounties, but we may do so in the future.

6. Priority Vulnerabilities

We are most interested in: authentication bypass; injection vulnerabilities (SQL, command, LDAP); exposure of personal or biometric data; privilege escalation; and vulnerabilities in the CJIS-adjacent data access paths.