Vulnerability Disclosure Policy

We build a security company. We take security reports on our own systems seriously. This page covers what is in scope, how to reach us, and what to expect once you file a report.

Report: jackson@zypher.sh
First response: within 3 business days
Scope: zypher.sh and all subdomains

Scope

The following assets are in scope for testing:

Anything else is out of scope. That includes:

What we care about

We are most interested in issues that lead to concrete impact. In rough priority order:

  1. Remote code execution or command injection
  2. Authentication or authorization bypass
  3. SQL, NoSQL, or template injection with meaningful reach
  4. Server-side request forgery, XML external entity, deserialization
  5. Cross-site scripting with a realistic exploitation path
  6. Sensitive data exposure or account takeover primitives
  7. Business logic flaws that map to real financial or reputational impact

Out of scope findings

The following are noted but generally will not receive a formal acknowledgement unless part of a chained exploit:

Rules of engagement

Please:

Safe harbor

If you make a good-faith effort to comply with this policy while researching a vulnerability, we consider your research authorized. Specifically:

Good faith does not extend to actions that are clearly outside the scope of research: destroying data, exfiltrating sensitive information beyond what a single proof of concept requires, or attempting to extract payment as a condition of disclosure. That is extortion, not disclosure.

How to report

Send an email to jackson@zypher.sh. Include:

What to expect

Recognition

Zypher does not run a paid bug bounty on its own site. Researchers who file valid reports and cooperate through remediation will be listed on our research page with their preferred handle. If you would rather stay anonymous, tell us and we will keep it that way.

Contact

jackson@zypher.sh

This policy is designed to align with RFC 9116. See our security.txt for the machine-readable version.