How to report
Email info@zenxecure.com with enough detail for us to reproduce the issue. Please include:
- the affected domain, endpoint, product or component;
- a clear description of the vulnerability and its impact;
- step-by-step reproduction instructions, including any payloads used;
- supporting evidence such as request/response captures or screenshots; and
- how you would like to be credited, if at all.
What you can expect from us
| Stage | Our commitment |
|---|---|
| Acknowledgement | Within 2 business days |
| Initial triage and severity assessment | Within 5 business days |
| Status updates | At least every 10 business days until resolution |
| Remediation target | Critical: 7 days · High: 30 days · Medium: 90 days, from confirmed triage |
We will tell you when the issue is fixed, and we are happy to credit you publicly once remediation is complete, if you would like that.
Safe harbour
If you make a good-faith effort to comply with this policy during your research, we will consider your research authorised, will not pursue or support legal action against you in relation to it, and will work with you if a third party does. If you are unsure whether an action is permitted, ask us first.
Ground rules
- Only test against assets you are confident belong to Zenxecure, or against your own tenant.
- Do not access, modify, exfiltrate or retain data belonging to anyone else. If you encounter personal data, stop and tell us immediately.
- Do not degrade our services — no denial of service, no resource exhaustion, no high-volume automated scanning against production.
- No social engineering, phishing or physical attacks against our staff, customers or offices.
- Give us a reasonable opportunity to remediate before any public disclosure, and coordinate the timing with us.
Out of scope
The following generally do not qualify unless you can demonstrate a concrete security impact:
- Missing security headers or cookie flags with no demonstrated exploit.
- Reports generated purely by an automated scanner, without validation.
- Weaknesses requiring a rooted or jailbroken device, physical access, or a highly improbable user interaction.
- Email configuration findings such as SPF, DKIM or DMARC policy strength.
- Self-XSS, clickjacking on pages with no sensitive action, and rate-limiting on non-authentication endpoints.
- Vulnerabilities in third-party services we do not control.
Encryption
If your report contains sensitive detail, ask us for our PGP key before sending and we will provide it. Please do not include exploit payloads targeting live customer tenants in plaintext email.
Our own reporting obligations
Where an incident falls within the scope of the CERT-In directions of 28 April 2022 or the breach notification requirements of the Digital Personal Data Protection Act, 2023, we report it within the prescribed timelines. Affected customers are notified directly.