01Reporting a security issue
If you believe you have found a vulnerability affecting a public system owned and operated by ZYFORTE, email info@zyforte.com with the subject “Security report.” Do not include passwords, private keys, customer information, or unnecessary personal data.
Include the affected URL or asset, a concise description, reproduction steps, potential impact, and safe supporting evidence. Please provide a reliable way for our security team to contact you.
02Good-faith research
ZYFORTE supports good-faith security research performed to improve safety. Research should minimize risk, preserve privacy, and stop when access to sensitive information or service disruption becomes possible.
- Test only public systems that ZYFORTE clearly owns or operates.
- Use the minimum interaction needed to demonstrate the issue.
- Do not access, alter, download, retain, or disclose data belonging to another person or organization.
- Do not use denial of service, social engineering, physical intrusion, malware, spam, or destructive testing.
- Allow reasonable time for investigation and remediation before any public disclosure.
03Out of scope
The following generally do not demonstrate a material vulnerability unless accompanied by a specific, reproducible security impact.
- Automated scanner output without validation.
- Missing security headers or best-practice configuration observations without exploitation impact.
- Clickjacking on pages without sensitive actions.
- Rate-limit observations that do not create meaningful risk.
- Issues affecting third-party services or systems not operated by ZYFORTE.
04What you can expect
We will review credible reports, acknowledge receipt when contact details are available, and work to understand and address confirmed risk. Response and remediation time depend on severity, complexity, and affected systems.
This policy does not create a bug bounty, promise payment, authorize access beyond what is described, or change any existing agreement. ZYFORTE intends not to initiate legal action for good-faith research that follows this policy and applicable law.
05Coordinated disclosure
Please keep vulnerability details confidential while we investigate. If you plan to publish, coordinate timing and technical detail with us so users are not exposed to avoidable risk.
For the machine-readable reporting route, see zyforte.com/.well-known/security.txt.