Security
About this page
Machine-readable version at casazium.com/.well-known/security.txt (RFC 9116). This page is the human-readable policy it links to.
If you believe you've found a security vulnerability in the License Server (self-hosted or hosted), casazium.com, or docs.casazium.com, please report it privately rather than opening a public issue or posting about it.
How to report
Email bob@casazium.com with:
- What you found and why you think it's a vulnerability
- Steps to reproduce it
- The affected component (self-hosted server, hosted console, a specific API route, one of the public sites) and version or commit if you know it
- What you were able to access or do as a result, if anything
You don't need to include a proof-of-concept exploit — a clear description is enough to start with.
What to expect
Casazium is a one-person company. I aim to acknowledge a report within 2 business days and will follow up with what I find and, once fixed, when a patch or deploy is out. I'll credit you in the fix notes if you want that, or keep the report anonymous if you'd rather.
Please don't
- Access, modify, or delete data that isn't yours while testing
- Run automated scanners against the hosted service without asking first
- Publicly disclose a vulnerability before it's fixed and you've heard back from me
Good-faith research
I won't pursue legal action against security research conducted in good faith under this policy — testing that doesn't access other customers' data, doesn't degrade the service for others, and is reported here rather than disclosed publicly first.
There's no paid bug bounty program at this time.
