ZoikoDigital
Responsible Disclosure

Report a potential ZoikoTime security vulnerability.

Review the current scope and rules before testing anything, then send potential vulnerability details through our protected security route.

Report a Potential Vulnerability

Policy Proof — Synthetic Example

Scope StatusNeeds Verification
Rules StatusNeeds Verification
Protected Intake StatusActive
Policy VersionPending Approval
Last Reviewed

This page is an approval candidate. Page access, this proof panel, or a submitted report never creates testing permission on their own.

Before you test: page access does not authorize testing.

Permission to test exists only as defined by the current approved policy, an in-scope asset record, its conditions, and the Rules of Engagement below. A brand, domain, product, customer relationship, or public endpoint does not automatically place every related asset in scope.

Third-party systems require their own authorization and are not covered here. Production, staging, sandbox, customer-managed, and partner-managed environments are separate scope dimensions. Viewing this page, clicking a link, submitting a report, or receiving a case reference never expands testing permission.

In-Scope Asset Registry

Current scope — synthetic example.

Illustrative record structure only. Real scope entries publish here only after policy approval.

Public web application

In Scope

Owner

Product Security

Environment

Production

Conditions

Test account required

Public API endpoints

Conditionally In Scope

Owner

Product Security

Environment

Production

Conditions

Rate-limited

Customer-managed integrations

Under Review

Owner

Third-party

Environment

Varies

Conditions

Provider authorization required

If you can't find an asset here, do not assume it's in scope. Report it through the protected route below and we'll clarify.

Out-of-Scope, Prohibited Testing & Rules of Engagement

What to avoid, and how to test in good faith.

Illustrative — not exhaustive

Prohibited & stop conditions

  • No load, stress, or denial-of-service testing
  • No destructive actions against production data
  • Stop immediately if customer or worker data is exposed
  • Social engineering and physical testing are not authorized without explicit approval

Rules of engagement

  • Use minimum necessary, least-invasive testing
  • Preserve reproducible evidence, not exhaustive capture
  • Report through the protected route below — keep evidence out of public view
  • Timelines are shown as milestones, never guaranteed countdowns
Safe Harbor & Data Handling

Good-faith research, and what we never ask for.

Safe-harbor language: pending Legal approval

Exact good-faith safe-harbor text must come from an approved Legal registry — it will display here once approved. This page does not paraphrase legal protection in a way that could expand authorization, confidentiality, or liability limits.

Data minimization

  • Never send us passwords, private keys, tokens, or credential dumps
  • Avoid unnecessary customer or worker data in your report
  • Reporters are never profiled, scored, or routed to sales for using this page
  • Attachments are scanned and access-controlled before review
Report Preparation Checklist

What helps us triage faster.

01

Affected asset

Which system or endpoint, from the scope registry above.

02

Environment

Production, staging, or another environment.

03

Description

What you observed, in plain language.

04

Impact assessment

Your read on what this could allow — evidence, not final severity.

05

Reproduction steps

Minimal steps to reproduce, if already known.

06

Safe supporting evidence

Screenshots or logs with sensitive data removed.

Protected Reporting

Submit a potential vulnerability report.

Never include passwords, private keys, tokens, or credential dumps in this form.

Report Responsibly

Found something? Review scope first, then report.

Authorization and scope come from current approved policy — not from this page alone.

Report a Potential Vulnerability