Anzar Technologies

Security

Last updated: October 10, 2026

Our commitment

Anzar Technologies LLC builds and operates mobile applications and web services used by people around the world. We take the security of our products and of our users' data seriously, and we welcome reports from security researchers who help us keep them safe.

Security contact

Security at Anzar Technologies is led by Yanis, Founder & Security Lead, who is responsible for vulnerability management, security reviews and incident response across our applications and services.

Email: contact@anzarsystems.com (please start the subject line with "[Security]")

Reporting a vulnerability

If you believe you have found a security vulnerability in one of our products, please send us:

  • The affected application, website or service, and its version if known
  • A description of the issue and its potential impact
  • Step-by-step instructions or a proof of concept to reproduce it
  • Any relevant screenshots, logs or request samples

Please do not disclose the issue publicly until we have had a reasonable opportunity to fix it.

What you can expect from us

  • Acknowledgement of your report within 3 business days
  • An initial assessment and, where applicable, an estimated fix timeline within 10 business days
  • Updates on our progress until the issue is resolved
  • Credit for your discovery once the fix is released, if you wish

Scope

This policy covers the mobile applications published by Anzar Technologies LLC on the App Store and Google Play, and the websites and backend services that support them.

The following are out of scope:

  • Denial-of-service attacks and volumetric testing
  • Social engineering, phishing or physical attacks against our staff or partners
  • Vulnerabilities in third-party services we rely on (please report those to the vendor)
  • Findings from automated scanners without a demonstrated impact

Safe harbor

We will not pursue legal action against researchers who act in good faith under this policy: who avoid privacy violations, data destruction and service disruption, who access only the minimum data needed to demonstrate the issue, who do not exploit it beyond that, and who give us reasonable time to fix it before any disclosure.

Rewards

We do not currently run a paid bug bounty program. We are grateful for every valid report and are happy to publicly acknowledge researchers who help us.