J Computer Solutions LLC welcomes responsible disclosure of security vulnerabilities. This policy provides safe harbor for researchers who identify and report issues in good faith.
Safe Harbor Statement
We will not pursue legal action against researchers who discover and responsibly disclose security vulnerabilities in accordance with this policy. We consider good-faith security research to be authorized activity under the Computer Fraud and Abuse Act (CFAA) and similar laws.
This policy covers the following systems:
Out of scope: third-party services (Stripe, cloud providers), social media accounts, and physical hardware not directly managed by J Computer Solutions LLC.
Submit vulnerability reports to security@projectaziz.com with the subject line "Vulnerability Disclosure." Your report should include:
You may also use our contact page to initiate a disclosure.
To qualify for safe harbor, researchers must:
With your permission, we will acknowledge researchers who report valid vulnerabilities in our security hall of fame. We do not currently offer monetary bug bounties, but we may do so in the future.
We are most interested in: authentication bypass; injection vulnerabilities (SQL, command, LDAP); exposure of personal or biometric data; privilege escalation; and vulnerabilities in the CJIS-adjacent data access paths.