Skip to main content

Security policy

Effective Nov 4, 2026Version v1

Draft: this text is under legal review and may change before it is final.

This is placeholder text. Qarabug's security policy is being written and has not been published yet. Until it is, the rules below are the ones Qarabug's own bug bounty programme publishes, and they apply to research on Qarabug itself.

What you may test. Test the platform you are reading this on. Sign up, file a report against your own test programme, and tell us what you find. Use accounts you created; do not touch another researcher's report, another company's programme, or anybody's bank details.

Rules. No automated scanning that a person would notice. No denial of service and no load testing. One record is a proof, a thousand is an incident. Report what you find to Qarabug and nowhere else until we have fixed it.

Safe harbour. We will not pursue legal action for research conducted under these rules and reported to us, and we will say so in writing to anyone who asks.

Disclosure. Coordinated disclosure ninety days after the fix ships, or earlier by agreement.

Out of scope. legacy.qarabug.az and everything behind it: the v1 application, served read-only for thirty days after the migration and no longer maintained. Third-party services we do not run: the identity provider, the mail provider and the payment provider.

Read in AzerbaijaniBack to home