Skip to content
Security

Responsible disclosure

Last updated: 15 September 2026

We build security products, so we hold our own systems to the standard we ask of others. If you have found a vulnerability in a Zenxecure system, we want to hear from you — and we will treat you well for telling us.

How to report

Email info@zenxecure.com with enough detail for us to reproduce the issue. Please include:

  • the affected domain, endpoint, product or component;
  • a clear description of the vulnerability and its impact;
  • step-by-step reproduction instructions, including any payloads used;
  • supporting evidence such as request/response captures or screenshots; and
  • how you would like to be credited, if at all.

What you can expect from us

StageOur commitment
AcknowledgementWithin 2 business days
Initial triage and severity assessmentWithin 5 business days
Status updatesAt least every 10 business days until resolution
Remediation targetCritical: 7 days · High: 30 days · Medium: 90 days, from confirmed triage

We will tell you when the issue is fixed, and we are happy to credit you publicly once remediation is complete, if you would like that.

Safe harbour

If you make a good-faith effort to comply with this policy during your research, we will consider your research authorised, will not pursue or support legal action against you in relation to it, and will work with you if a third party does. If you are unsure whether an action is permitted, ask us first.

Ground rules

  • Only test against assets you are confident belong to Zenxecure, or against your own tenant.
  • Do not access, modify, exfiltrate or retain data belonging to anyone else. If you encounter personal data, stop and tell us immediately.
  • Do not degrade our services — no denial of service, no resource exhaustion, no high-volume automated scanning against production.
  • No social engineering, phishing or physical attacks against our staff, customers or offices.
  • Give us a reasonable opportunity to remediate before any public disclosure, and coordinate the timing with us.

Out of scope

The following generally do not qualify unless you can demonstrate a concrete security impact:

  • Missing security headers or cookie flags with no demonstrated exploit.
  • Reports generated purely by an automated scanner, without validation.
  • Weaknesses requiring a rooted or jailbroken device, physical access, or a highly improbable user interaction.
  • Email configuration findings such as SPF, DKIM or DMARC policy strength.
  • Self-XSS, clickjacking on pages with no sensitive action, and rate-limiting on non-authentication endpoints.
  • Vulnerabilities in third-party services we do not control.

Encryption

If your report contains sensitive detail, ask us for our PGP key before sending and we will provide it. Please do not include exploit payloads targeting live customer tenants in plaintext email.

Our own reporting obligations

Where an incident falls within the scope of the CERT-In directions of 28 April 2022 or the breach notification requirements of the Digital Personal Data Protection Act, 2023, we report it within the prescribed timelines. Affected customers are notified directly.

A-0923, Tower A, Bhutani Cyber Park, Sector 62, Noida, Uttar Pradesh 201309, India