Legal

Security

Security researchers keep our customers safe. We treat coordinated disclosure as a first-class part of how we build. For our security posture, sub-processors, and data handling, see the Trust page.

Reporting a vulnerability

Email [email protected] with a clear description, reproduction steps, and any proof-of-concept. We acknowledge every report within one business day and share triage results within five business days.

For general questions that are not security-related, email [email protected].

Safe harbor

We will not pursue legal action against you for security research conducted in good faith and in line with the scope below. Good faith means:

  • Testing that does not degrade the service for other users.
  • Research on systems and endpoints listed under "In scope".
  • Reports made through the disclosure channel above, without publishing details before we have had a reasonable chance to fix.

In scope

  • zotniq.ai and its subdomains (dashboard, docs, API).
  • The Zotniq desktop agent, its update mechanism, and its local storage.
  • The Zotniq SDK and any published client libraries.

Out of scope

  • Third-party services and sub-processors listed on the Trust page. Please report to them directly.
  • Denial-of-service testing, physical attacks, social engineering of employees or customers.
  • Vulnerabilities that require a compromised device or account you do not own.
  • Reports generated by automated scanners without independent verification.
  • Missing security headers or best-practice recommendations without a demonstrable impact.

Please do not

  • Test against production customer data. If you need a test environment, ask and we will provide one.
  • Publish reports before we confirm a fix, or before a mutually agreed date.
  • Access, modify, or exfiltrate customer data beyond what is needed to demonstrate the issue.

Recognition

We acknowledge researchers who help us. We do not yet run a paid bounty program. When we do, terms will be posted here.