Security

Security bug disclosure.

We take the security of Axra seriously. If you've found a vulnerability, we want to hear from you — and we'll work with you to fix it quickly.

Our commitment to researchers

Security researchers play a vital role in keeping Axra and its users safe. We believe in responsible disclosure and commit to working transparently with anyone who identifies a legitimate vulnerability in our systems.

If you report a valid issue in good faith, we will:

  • Acknowledge your report within 48 hours
  • Provide an estimated timeline for a fix
  • Keep you informed as we work to resolve the issue
  • Credit you publicly if you wish, once the vulnerability is patched
  • Not take legal action against you for good-faith research

How to report a vulnerability

Send your report to security@useaxra.com. Please include as much detail as possible so we can reproduce and triage the issue quickly.

01Describe the issueWhat did you find? Include the vulnerability type (e.g. XSS, IDOR, auth bypass) and a clear description of the problem.
02Show us how to reproduce itProvide step-by-step reproduction instructions, affected URLs, request/response payloads, or a proof-of-concept.
03Describe the impactExplain what a malicious actor could do — which users, data, or funds are at risk.
04Give us time to fix itPlease wait for us to resolve the issue before publishing. We aim to patch critical issues within 7 days.

Severity classification

We triage reports using the following severity levels. Our response SLA is based on severity.

SeverityExamplesTarget patch time
CriticalAuthentication bypass, mass fund theft, full account takeover24 – 48 hours
HighPrivilege escalation, partial account takeover, sensitive data exposure7 days
MediumCSRF, stored XSS, information disclosure to authenticated users30 days
LowSelf-XSS, open redirect, clickjacking without sensitive action90 days

What's in scope

  • Axra web apps — the app, dashboard, and public marketing site
  • Axra mobile apps — iOS and Android applications
  • Axra Pay API — authentication, endpoint security, webhook integrity

Out of scope: social engineering, physical attacks, third-party services, volumetric DoS, and issues that require jailbroken devices.

Responsible disclosure rules

To qualify for recognition and avoid legal risk, please follow these rules during your research:

  • Only test against accounts you own or have explicit permission to test
  • Do not access, modify, or delete user data that is not yours
  • Do not perform denial-of-service attacks or degrade service availability
  • Do not exfiltrate data beyond what is needed to demonstrate the vulnerability
  • Do not disclose the vulnerability publicly until we have issued a fix

Note: We do not currently offer a cash bug bounty, but we do offer public credit, Axra Pro subscriptions, and our sincere gratitude for responsible disclosures.

Ready to report?

Email our security team with full details of what you found.

Email security@useaxra.com