Security & Vulnerability Disclosure
ASJi One is committed to robust cybersecurity practices. We welcome bug reports from independent security researchers, ethical hackers, and security engineers to keep our platform and users safe.
Last updated 28 July 2026 · Maintained by ASJi One
1. Official security.txt (RFC 9116 Standard)
In accordance with RFC 9116, our machine-readable security contact information is published at both /.well-known/security.txt and /security.txt.
Contact: mailto:security@asji.law
Contact: mailto:asji.online@gmail.com
Expires: 2027-12-31T23:59:59.000Z
Preferred-Languages: en, ar, hi
Canonical: https://asji-one.vercel.app/.well-known/security.txt
Policy: https://asji-one.vercel.app/legal/security
Hiring: https://asji-one.vercel.app2. Coordinated Vulnerability Disclosure (CVD)
We follow Coordinated Vulnerability Disclosure principles. When reporting a potential security issue, please adhere to the following guidelines:
- •Send detailed vulnerability details to security@asji.law or asji.online@gmail.com.
- •Provide step-by-step reproduction instructions or proof-of-concept (PoC) scripts.
- •Allow us a reasonable timeframe (minimum 30 days) to address and remediate the issue before public disclosure.
- •Do not access or modify user data, perform denial of service (DoS/DDoS) attacks, or execute social engineering.
3. Safe Harbor Framework
If you conduct security research in good faith and in compliance with this policy, we consider your research to be authorized. We will not initiate legal action against researchers for accidental, good-faith violations of security testing constraints.
4. Vulnerability Response SLA
Initial acknowledgment within 24 business hours. Triage and severity assessment within 72 hours.
Aligned with ISO/IEC 29147 (Vulnerability disclosure) and ISO/IEC 30111 (Vulnerability handling).