1. Our Commitment
Azra is a Discord bot and web dashboard operated by Bluebell Solutions LLP
("Bluebell", "we", "us", "our"). We take the security of our platform — and the Discord servers
and members that rely on it — seriously. We welcome reports from security researchers and members
of the community, and we are committed to working with you to verify, reproduce, and remediate
legitimate vulnerabilities promptly.
This policy explains what systems are in scope, how to report an issue responsibly, and what you can
expect from us in return.
2. Scope
The following assets are in scope for security reports:
- The Azra web dashboard and its API (the application served from our primary domain)
- The Azra Discord bot and its command, event, and interaction handlers
- Authentication and session handling (Discord OAuth2, the signed session cookie, and the server-side session store)
- Payment and subscription flows, including coupon, affiliate, and payout logic
- Server-to-server integrations and the loopback cache-invalidation channel
We are particularly interested in reports concerning:
- Authentication or authorization bypass, including cross-guild access (BOLA/IDOR) where one user can read or modify another server's configuration
- Injection flaws (SQL, command, template, or cross-site scripting)
- Cross-Site Request Forgery (CSRF) on state-changing endpoints
- Exposure of secrets, access tokens, encrypted PAN data, or other sensitive information
- Privilege escalation within the dashboard or the bot's permission model
- Logic flaws in payments, commissions, or payouts that could lead to financial loss
3. Out of Scope
The following are generally not eligible and should not be tested:
- Denial-of-service (DoS/DDoS), volumetric, or resource-exhaustion attacks
- Social engineering, phishing, or physical attacks against Bluebell staff or infrastructure
- Spam, brute-force, or automated scanning that degrades service for other users
- Vulnerabilities in third-party services we depend on (Discord, Razorpay, OpenAI, Twitch, YouTube) — report those to the respective vendor
- Missing security headers, cookie flags, or TLS configuration issues with no demonstrable impact
- Reports from automated tools without a working proof of concept or clear exploit path
- Self-XSS that cannot be used to attack another user, and clickjacking on pages with no sensitive actions
4. How to Report
Email a detailed report to [email protected].
If you do not receive an acknowledgement within three business days, you may follow up via
[email protected].
A good report includes:
- A clear description of the vulnerability and its potential impact
- Step-by-step instructions to reproduce it, including any required accounts or preconditions
- A minimal proof of concept (request samples, scripts, or screenshots)
- The affected URL, endpoint, command, or component
- Your assessment of severity and any suggested remediation
Please report each distinct issue separately, and give us a reasonable opportunity to remediate
before any public disclosure.
5. Safe Harbour
We will not pursue or support legal action against researchers who, in good faith, discover and report
vulnerabilities in accordance with this policy. We consider activity conducted under this policy to be
authorized, and we will work with you to understand and resolve the issue quickly. This safe harbour does
not apply to activity that intentionally harms our users, accesses data beyond what is necessary to
demonstrate a vulnerability, or violates applicable law.
6. Researcher Guidelines
To stay within this policy, you agree to:
- Only test against accounts and servers you own or have explicit permission to test
- Avoid accessing, modifying, or deleting data that does not belong to you — use the minimum interaction needed to prove an issue
- Never run attacks that could degrade, disrupt, or take down the service for others
- Keep details of any vulnerability confidential until we confirm it has been resolved
- Not exfiltrate data, establish persistence, or pivot to other systems
- Comply with all applicable laws
7. What to Expect From Us
| Stage | Our Target |
| Acknowledge your report | Within 3 business days |
| Initial triage & severity assessment | Within 7 business days |
| Status updates during remediation | Periodically until resolved |
| Fix verification & closure | As soon as a fix is deployed and confirmed |
We will keep you informed of our progress and will let you know when the issue is resolved. With your
permission, we are happy to credit you once a fix is live.
8. Recognition & Rewards
Azra does not currently run a paid bug-bounty program. We deeply value responsible disclosure and will,
at our discretion, publicly acknowledge researchers who report valid, previously unknown vulnerabilities
— unless you prefer to remain anonymous. Any monetary recognition, where offered, is granted entirely at
our discretion.
Security reports: [email protected]
General support: [email protected]
Bluebell Solutions LLP