This page states Azari Holdings’ public policy position. Applicable law, contracts, regulatory requirements and more specific subsidiary procedures may impose additional or stricter requirements.
Risk-based security
Security effort should reflect the sensitivity of information, criticality of the service, threat environment and consequences of failure. A public brochure site and a financial-services ledger require different controls even though both sit within the group.
Businesses should identify critical systems and data rather than assume every asset has the same risk.
Identity and access
Access should be tied to legitimate roles, protected with appropriate authentication and removed when no longer required. Privileged access deserves stronger control and oversight because misuse can have wider consequences.
Shared credentials and unnecessary standing access should be avoided where practical.
Data protection
Sensitive information should be protected in storage, transit and use in a manner appropriate to risk. Secrets, credentials and personal data should not be committed to public source code or exposed through logs and error messages.
Data minimisation reduces both privacy and security exposure.
Secure development and change
Software and infrastructure changes should be reviewed and tested proportionately before production. Dependencies should be maintained, secrets separated from code and production debugging or unsafe defaults disabled.
Security testing should be authorised and designed to avoid unnecessary risk to live customers or data.
Incident response
Suspected compromise, data exposure, fraud or material service disruption should be contained, escalated and investigated with enough logging and evidence to understand what happened.
Response should include restoration, communication, required notification and corrective action rather than focusing only on immediate recovery.
Third-party security
Technology providers and other third parties can become part of Azari’s attack surface. Material providers should be assessed for the access, data and operational dependency they create.
Contracts and exit planning should address security responsibilities where the relationship warrants it.
Reporting security concerns
Good-faith security reports should be sent privately to hello@azariholdings.com with enough detail to reproduce or understand the issue. Do not exploit the issue beyond what is necessary to demonstrate it or access data that is not yours.
Azari does not promise a bug bounty through this statement; any reward programme would be published separately if introduced.
