1. Contact channels and triage matrix
Technical Bug Reports
Email hello@czoa.com for workspace errors, incorrect output, broken downloads, browser compatibility, accessibility, or translation defects.
Algorithmic & Mathematical Feedback
Email hello@czoa.com with the exact input, actual output, independently calculated expected output, and a primary specification or test vector when available.
Security disclosures
Email security@czoa.com. The machine-readable disclosure contact is published at /.well-known/security.txt in the format described by RFC 9116.
2. Before sending a report
- Remove passwords, API keys, customer data, private documents, and other confidential material.
- Reduce the input to the smallest example that still reproduces the issue.
- Include the tool URL, browser name and version, operating system, and exact error text.
- For downloaded files, describe how you checked the artifact and which application rejected it.
3. Bug report template
[Bug Report Submission Template] 1. Tool name and URL: 2. Browser, version, and operating system: 3. Sanitized minimal input: 4. Steps to reproduce: 5. Actual output or error: 6. Expected output and reference: 7. Does the issue reproduce after a reload?
4. Response policy and SLA boundary
CZOA Tools is an independent project and does not offer a contractual SLA. Security reports and reproducible calculation errors are prioritized. A first review may take 24 to 48 business hours, while ordinary bug reports, feature suggestions, and translation corrections can take longer. These are review targets, not guaranteed response or repair times.
5. Security research scope
Report vulnerabilities without accessing another person's data, degrading service, or using destructive testing. The security.txt file lists the current contact and policy URL. It does not advertise a PGP key, paid bounty, legal safe-harbor contract, or guaranteed remediation window.
6. Processing evidence
Tool payload processing is designed to occur in the browser, but the page may still load site assets, analytics, or advertising. When a privacy boundary matters, inspect the browser Network panel and the current Privacy Policy. Do not include sensitive input in a support email.
