Security

Report a vulnerability

If you’ve found a security issue in Barzaman, thank you for helping. Please report it to us confidentially.

[email protected]

How to report

  1. Email [email protected] (English, Persian or Arabic).
  2. Describe the issue, steps to reproduce and the likely impact.
  3. Keep the details private until we’ve fixed it.

Scope

  • barzaman.ir and its subdomains (app, api, admin)
  • The Barzaman Android app and web app

Out of scope

  • Denial-of-service attacks and load testing
  • Social engineering or targeting staff and users
  • Accessing other users’ data beyond the minimum needed to demonstrate the issue

Our commitment

  • We’ll acknowledge your report and keep you updated.
  • We won’t take legal action against good-faith research that follows this page.
  • Once fixed, we’ll credit you publicly if you’d like.

How we protect data

  • On-device database encryption and encrypted connections to our servers
  • No ads, trackers or third-party resources in the website or app
  • Short-lived tokens and step-up verification before sensitive actions
  • No sign-in codes, tokens or user content in system logs

Machine-readable version: /.well-known/security.txt