ZeroFlaw helps others find security flaws. That is why we welcome every report of a vulnerability in our own service and handle reports quickly, confidentially and fairly.
Found a vulnerability? Write to [set legal.email in config.php]. Our contact details are also available in machine-readable form in our security.txt (RFC 9116).
How to report a vulnerability
To help us reproduce the problem quickly, please describe:
- the affected address, feature or API route,
- the steps to reproduce the problem,
- the possible impact (what could an attacker achieve?),
- a proof of concept, screenshots or requests and responses, if available.
Our commitments
- We confirm receipt of your report within three business days.
- Within ten business days you receive our assessment and an estimated timeline for the fix.
- We keep you updated on the progress and tell you when the vulnerability has been fixed.
- If you follow the rules below, we will not take legal action against you or file a criminal complaint.
- If you wish, we will credit you as the finder after the fix.
We currently do not offer a paid bug bounty program.
Rules
- Only test with your own accounts. Do not access other users' data and do not change or delete data that is not yours. If you accidentally come across other people's data, stop testing, report it to us and delete the data.
- No attacks on availability (denial of service), no load tests and no automated scans with a high request rate.
- No social engineering, no phishing, no attacks on our staff, premises or service providers.
- Only exploit a vulnerability as far as necessary to prove it.
- Only publish details after the vulnerability has been fixed or after agreeing with us, at the latest after 90 days.
Scope
In scope: the application at https://zeroflaw.net including dashboard, sign-in, API (/api/) and status page.
Out of scope:
- third-party services such as Stripe, GitHub or Google (please report directly to them),
- findings without demonstrable impact, such as missing headers on static pages or version information,
- self-XSS, clickjacking on pages without sensitive actions and logout CSRF,
- output of automated scanners without confirmation,
- issues that only occur in outdated or unsupported browsers.
How we protect your data
- Transmission only via TLS with HSTS, strict Content Security Policy, no third-party scripts or fonts.
- Sensitive content such as finding descriptions, code snippets and notes encrypted with AES-256-GCM.
- Passwords as Argon2id hashes, tokens only as hashes, two-factor sign-in for all accounts.
- Uploaded source code is deleted after the scan, found secrets are masked.
- Live scans only for domains whose control has been proven.
More details in the privacy policy and in Annex 1 of the data processing agreement.