Legal
Security
Security researchers keep our customers safe. We treat coordinated disclosure as a first-class part of how we build. For our security posture, sub-processors, and data handling, see the Trust page.
Reporting a vulnerability
Email [email protected] with a clear description, reproduction steps, and any proof-of-concept. We acknowledge every report within one business day and share triage results within five business days.
For general questions that are not security-related, email [email protected].
Safe harbor
We will not pursue legal action against you for security research conducted in good faith and in line with the scope below. Good faith means:
- Testing that does not degrade the service for other users.
- Research on systems and endpoints listed under "In scope".
- Reports made through the disclosure channel above, without publishing details before we have had a reasonable chance to fix.
In scope
zotniq.aiand its subdomains (dashboard, docs, API).- The Zotniq desktop agent, its update mechanism, and its local storage.
- The Zotniq SDK and any published client libraries.
Out of scope
- Third-party services and sub-processors listed on the Trust page. Please report to them directly.
- Denial-of-service testing, physical attacks, social engineering of employees or customers.
- Vulnerabilities that require a compromised device or account you do not own.
- Reports generated by automated scanners without independent verification.
- Missing security headers or best-practice recommendations without a demonstrable impact.
Please do not
- Test against production customer data. If you need a test environment, ask and we will provide one.
- Publish reports before we confirm a fix, or before a mutually agreed date.
- Access, modify, or exfiltrate customer data beyond what is needed to demonstrate the issue.
Recognition
We acknowledge researchers who help us. We do not yet run a paid bounty program. When we do, terms will be posted here.