Legal
Security Vulnerability Reporting
Found a vulnerability in ZeeZoom? How to report it, what we commit to, and what we ask of you.
Last updated: September 23, 2026 · This is a translation. If it conflicts with the Hebrew version, the Hebrew version prevails.
Draft: some company details are still missing (highlighted). This page stays out of search engines until they are filled in.
How to report
Email [email protected]. We are grateful to everyone who helps keep our users safe.
- A description of the issue and its possible impact.
- The affected URL or component, and steps to reproduce.
- A proof of concept (screenshot, request or video) — without other users’ data.
- How to reach you, and — if you like — how to credit you.
This address is also published in /.well-known/security.txt per RFC 9116.
In scope
zeezoom.app and its subdomains, our API, share links, and the sign-in and payment flows on our side.
Out of scope: third-party services (such as Supabase, Paddle, Vercel and AI providers) — report to them directly; denial of service; social engineering and phishing; spam; findings without real impact (such as missing security headers alone or self-XSS).
Good-faith research rules
- Test only with accounts you own. Do not access, modify or delete others’ data beyond the minimum needed to demonstrate the issue.
- No denial of service, heavy automated scanning, or attempts to bypass credit charges for gain.
- Do not target employees or users with social engineering.
- Give us reasonable time to fix before public disclosure — usually up to 90 days — and coordinate disclosure with us.
What we commit to
- Acknowledge your report within 3 business days.
- Give an initial assessment within 10 business days and keep you updated until it is fixed.
- Prioritize fixes by severity.
- Credit you publicly, with your consent.
Research done in good faith and in line with this policy is authorized as far as we are concerned, and we will not initiate legal action against it.
We do not currently run a paid bug bounty program.
Other reports
Data leaks or privacy concerns — [email protected]. Abusive or infringing content — [email protected]. Account problems — [email protected].