Security contact, incidents and legal documents
Updated September 7, 2026
How to report a vulnerability, what happens after you do, how you are told if an incident affects your tenant, and where the legal documents are. Reports go straight to the engineer who maintains the code, with no triage queue in between.
Reporting a vulnerability
Email contact@aztokenwatch.com with “Security” in the subject line.
Include where possible:
- The finding and steps to reproduce it.
- The affected host —
app.aztokenwatch.com(the product) oraztokenwatch.com(this marketing site). - Your assessment of impact, and whether you believe data was exposed.
- How you would like to be credited, if at all.
Do not run automated scans that degrade service for other customers, and do not access, modify or retain data belonging to another tenant. Good-faith research reported this way will not be met with legal action.
Response targets
| Acknowledgement | Within 2 business days, from a person rather than an autoresponder. |
|---|---|
| Initial assessment | Within 5 business days: confirmation status, severity rating, and next steps. |
| Fix and disclosure | Timing depends on severity. You are notified when the fix ships, and credited on request. |
If a target is going to slip, you are told.
Blast radius
- An attacker holding the database gets credential metadata: application and credential names, key ids, and expiry dates. Client secret values and certificate private keys are never received, so they are not there to take.
- An attacker holding the Graph access can read App Registrations. The permission cannot create a credential, modify an application, or grant anything.
- The exposure is enumerable in advance: the data page is the complete list of what exists to lose.
An inventory of expiry dates still carries reconnaissance value, since it shows which applications matter and which credentials are due for rotation.
Incident notification
If an incident affects data belonging to your tenant, your tenant administrators and billing contact are notified by email without undue delay and within 72 hours of confirmation.
The notification states:
- what happened, and when it was discovered;
- which of your data was involved, itemised against the data inventory;
- what has been done in response; and
- what action is recommended on your side, including whether credential rotation is warranted.
If scope is still being established, a first notification is sent inside the window with what is known at that point, followed by updates.
Legal documents
| Privacy policy | aztokenwatch.com/privacy — what is collected, how it is used, retention, international transfers, and your rights. |
|---|---|
| Terms of service | aztokenwatch.com/terms |
| Refund policy | aztokenwatch.com/refund |
| Data controller | Maksym Vostruhin, individual entrepreneur registered in Ukraine. Full registration details on request. |
Data processing agreement
A signed DPA can be arranged — email contact@aztokenwatch.com, preferably before sign-up.
Certifications
Token Watch holds no SOC 2, ISO 27001, or comparable certification, and does not claim to. The control areas those audits examine are implemented and documented, including audit logging, least privilege, encryption, retention and the incident handling on this page. See certifications and security controls for what is in place for each, and for what a missing certificate does and does not tell you.
Other questions
Security questionnaires, architecture follow-ups, or anything not covered here: contact@aztokenwatch.com.
Token Watch