Public web application
In ScopeOwner
Product Security
Environment
Production
Conditions
Test account required
Review the current scope and rules before testing anything, then send potential vulnerability details through our protected security route.
Report a Potential VulnerabilityThis page is an approval candidate. Page access, this proof panel, or a submitted report never creates testing permission on their own.
You've found something that looks like a security flaw in ZoikoTime.
This is the right route →Unauthorized access happening now — do not test further.
Go to urgent account route →Something is down or degraded — this isn't necessarily a vulnerability.
Go to System Status →Misuse of the platform, not a technical flaw.
Go to Acceptable Use →Questions about how data is collected or used.
Go to Privacy →A harmful AI output without a security flaw.
Go to AI Governance →Something isn't working as expected, with no security impact.
Go to Support →Affects a provider or integration, not a first-party ZoikoTime component.
Go to provider's route →Tell us what you found — we'll route it internally without forcing a resubmission.
Report and we'll route it →Permission to test exists only as defined by the current approved policy, an in-scope asset record, its conditions, and the Rules of Engagement below. A brand, domain, product, customer relationship, or public endpoint does not automatically place every related asset in scope.
Third-party systems require their own authorization and are not covered here. Production, staging, sandbox, customer-managed, and partner-managed environments are separate scope dimensions. Viewing this page, clicking a link, submitting a report, or receiving a case reference never expands testing permission.
Illustrative record structure only. Real scope entries publish here only after policy approval.
Owner
Product Security
Environment
Production
Conditions
Test account required
Owner
Product Security
Environment
Production
Conditions
Rate-limited
Owner
Third-party
Environment
Varies
Conditions
Provider authorization required
If you can't find an asset here, do not assume it's in scope. Report it through the protected route below and we'll clarify.
Exact good-faith safe-harbor text must come from an approved Legal registry — it will display here once approved. This page does not paraphrase legal protection in a way that could expand authorization, confidentiality, or liability limits.
Which system or endpoint, from the scope registry above.
Production, staging, or another environment.
What you observed, in plain language.
Your read on what this could allow — evidence, not final severity.
Minimal steps to reproduce, if already known.
Screenshots or logs with sensitive data removed.
Authorization and scope come from current approved policy — not from this page alone.
Report a Potential Vulnerability