Private security contact

Report a security concern privately.

Use this route for suspected account compromise, possible data exposure, unauthorized admin activity, authentication or access bypass, malicious Asiara links, or a vulnerability affecting the product.

Do not disclose a vulnerability publicly.

Send security concerns to security@asiara.app, not Discord, social media, or a public issue tracker.

Report scope

Concerns that belong here

Account or data

Suspected account compromise, session exposure, private data exposure, or another user seeing information they should not see.

Access or administration

Unauthorized admin activity, role or beta-access bypass, malicious impersonation, or a link pretending to be Asiara.

Vulnerability

A reproducible flaw affecting authentication, authorization, privacy, notifications, public content, or service integrity.

Useful evidence

Describe the issue without exposing secrets.

  • A clear, safe description of what happened.
  • Date, time, and timezone observed.
  • App version or build, platform, and affected screen or public URL.
  • Minimal reproduction steps that do not access or change another person's data.
  • A safely redacted screenshot or recording, if useful.
  • A private reply contact.

Safe testing boundary

Stop after demonstrating the concern safely.

  • Do not retain, modify, delete, or disclose another person's data.
  • Do not create persistence, disrupt service, or contact affected users.
  • Do not continue testing after Asiara asks you to stop.
  • No bug bounty or payment is promised unless a separate reviewed program is published.

Security contact

Use the dedicated incoming route.

security@asiara.app is live and tested for incoming mail. A separate backup escalation route is not configured yet, and no guaranteed response time is promised.