Report a Security Vulnerability
How to responsibly report a security vulnerability found on the Im Paharan website, which rules to follow, and what we commit to in return.
Provisional version: this text is under legal review and may change.
Version of 01.10.2026 · The Armenian version prevails; this translation is provided for convenience. Read the Armenian version
Contents
1.Scope#
We are grateful to everyone who helps us improve the security of our website in good faith. This page sets out the rules for reporting vulnerabilities.
These rules apply to the Im Paharan website and to the application programming interfaces (APIs) used by the website.
They do not apply to third-party services (for example, the hosting provider or email services). Please report vulnerabilities in those services directly to the provider concerned.
2.How to report#
Write to security@impaharan.am not yet active and include:
- a description of the vulnerability and its type;
- the steps to reproduce it (where needed, the requests or code used);
- the potential impact, in other words what an attacker could do;
- the address (URL) of the affected page or interface;
- your contact details and, if you wish, the name under which we may credit you.
Do not include other people’s personal data in your report. If such data became accessible to you by accident, state only the type of data (for example, “email addresses”), not the data itself.
You may write in Armenian, Russian or English. Our contact details are also published in machine-readable form in the /.well-known/security.txt file.
3.Good-faith rules#
When looking for a vulnerability and reporting it, please follow these rules:
- Act in good faith and solely for the purpose of improving security.
- Access the system only to the extent necessary to demonstrate the vulnerability. Never view, modify, copy or delete other members’ data.
- Use only your own test accounts. Do not log in to anyone else’s account.
- Do not carry out denial-of-service (DoS) attacks, send large volumes of requests, or guess passwords by brute force. The website’s automatic protections block the IP addresses from which such activity originates.
- Do not use social engineering, phishing or physical attacks against our staff, members, premises or equipment.
- As soon as the vulnerability is confirmed, stop testing and let us know.
- Do not publish or share information about the vulnerability with third parties until it has been fixed. Agree the publication date with us: as a rule, it is no later than 90 days after your report.
- Do not use the vulnerability to obtain any benefit, to cause harm to us or to others, or to make threats.
4.What does not count as a vulnerability#
As a rule, the following reports are not accepted as vulnerabilities for the purposes of these rules:
- denial-of-service (DoS) attacks and load testing;
- the ability to send spam or mass emails;
- missing HTTP security headers without a demonstrated impact;
- self-XSS, in other words code execution that requires the user to paste the code into their own browser;
- clickjacking on pages that contain no sensitive actions;
- vulnerabilities in third-party services;
- reports generated by automated tools that have not been verified manually.
5.Our commitments#
- We will acknowledge receipt of your report within 3 working days.
- We will assess the vulnerability and keep you regularly informed of progress towards fixing it.
- We will fix the vulnerability within a timeframe proportionate to its severity.
- If you wish, we will publicly thank you and mention your name.
- We do not offer financial rewards at this time.
- We will use your data only to handle your report and will not share it with third parties without your consent, except where required by law.
If it turns out that the vulnerability has led to a personal data breach, we will fulfil the obligations laid down in Article 21(4) of the Law of the Republic of Armenia on Protection of Personal Data No. HO-49-N of 18.05.2015: an immediate public statement, notification of the police and of the Personal Data Protection Agency, and notification of the members concerned.
Im Paharan will not bring legal action against, or file a complaint with law enforcement authorities about, any person who discovers a vulnerability and reports it to us in good faith and in compliance with these rules. This commitment applies only to Im Paharan and cannot bind public authorities or third parties.
6.For other matters#
The address security@impaharan.am not yet active is intended for technical vulnerabilities only. For account problems (for example, if you cannot log in), suspected fraud or a dispute about an order, please use the Tips for safe transactions and Complaints and Disputes pages, or write to support@impaharan.am not yet active.