Infrastructure Hardening & Vulnerability Disclosure
Security & Responsible Disclosure
Last Updated: March 2025 • Statutory Version 2.0
Muhammad Tahir Zaman Ltd (Company No. 16821325) prioritizes the privacy, confidentiality, and technical integrity of our creators and web visitors. This document details our platform defense architecture and safe harbor protocol for ethical cybersecurity researchers.
1. Platform Security Measures
- Transport Layer Security (TLS 1.3): All network traffic across our domains is strictly encrypted in transit using modern TLS ciphers with HSTS preloading enabled.
- Zero Password / Credential Storage: We never request, process, or store credit card PINs or online banking login credentials on our website. All payout conduits (Wise, PayPal, Tide) are authorized directly on official financial partner gateways.
- Client-Side Rate Limiting & Honeypot Defense: Our consultation gateways utilize honeypot inputs and client-side cooldown algorithms to thwart automated bots and brute-force scans.
- Content Security Policy (CSP): Headers are configured to prevent malicious script injection, clickjacking, and unauthorized cross-origin framing.
2. Responsible Disclosure Safe Harbor
We welcome reports from ethical security researchers. If you discover a potential vulnerability within our web assets, we commit to not pursuing legal action provided you adhere to the following guidelines:
- Do not compromise client privacy or disrupt public services (no DDoS attacks).
- Do not destroy, modify, or download sensitive database records.
- Allow our engineering team reasonable time (minimum 30 days) to address the issue prior to public disclosure.
- Avoid performing social engineering or phishing attacks against our personnel.
3. How to Submit a Vulnerability Report
Security Desk Dispatch
Email reports to: muhammadtahirzaman.ltd@gmail.com
Include reproduction steps, proof-of-concept payload, and browser environment. We acknowledge reports within 48 hours.