We build a security company. We take security reports on our own systems seriously. This page covers what is in scope, how to reach us, and what to expect once you file a report.
Report:jackson@zypher.sh First response: within 3 business days Scope:zypher.sh and all subdomains
Scope
The following assets are in scope for testing:
zypher.sh
All subdomains of zypher.sh
Any software Zypher publishes under our GitHub organization
Anything else is out of scope. That includes:
Third-party services we happen to use (video CDNs, form providers, font hosts, analytics)
Client environments we have assessed or currently assess. If you believe you have found a vulnerability affecting a Zypher client, contact us and we will route it to the correct disclosure channel.
Social engineering, phishing, physical intrusion, or anything targeting Zypher staff outside of the assets listed above
What we care about
We are most interested in issues that lead to concrete impact. In rough priority order:
Remote code execution or command injection
Authentication or authorization bypass
SQL, NoSQL, or template injection with meaningful reach
Server-side request forgery, XML external entity, deserialization
Cross-site scripting with a realistic exploitation path
Sensitive data exposure or account takeover primitives
Business logic flaws that map to real financial or reputational impact
Out of scope findings
The following are noted but generally will not receive a formal acknowledgement unless part of a chained exploit:
Missing security headers on static assets when no exploitation path is shown
SPF, DKIM, or DMARC configuration observations without a working spoof
Rate limiting reports without a business-impact scenario
Self-XSS reports without an escalation chain
Open redirect on non-authenticated endpoints with no downstream impact
Descriptive error messages that leak framework versions
Findings from automated scanners with no manual validation
Rules of engagement
Please:
Test only against assets that are explicitly in scope
Avoid actions that would degrade service for real users. Rate limit yourself.
Do not access, modify, or destroy data that does not belong to you. If a proof of concept accidentally pulls other users' data, stop, tell us, and delete your copy.
Do not run persistent implants, backdoors, or resource-heavy processes on our infrastructure
Do not publicly disclose an unpatched vulnerability before we have had time to respond
Safe harbor
If you make a good-faith effort to comply with this policy while researching a vulnerability, we consider your research authorized. Specifically:
We will not pursue civil action against you
We will not initiate a complaint to law enforcement
We will work with you if any third party takes action
Good faith does not extend to actions that are clearly outside the scope of research: destroying data, exfiltrating sensitive information beyond what a single proof of concept requires, or attempting to extract payment as a condition of disclosure. That is extortion, not disclosure.
Reproduction steps and any proof of concept code or screenshots
The affected URL, endpoint, or component
The impact you have verified (not just the impact you suspect)
Contact details you would like used for follow-up and acknowledgment
What to expect
First response: within 3 business days
Triage and severity confirmation: within 10 business days for critical and high severity issues
Remediation timeline: shared once triage is complete
Coordinated disclosure: we will work with you on public disclosure once the fix has shipped. Default is 90 days from initial report, with room to move either way based on complexity.
Recognition
Zypher does not run a paid bug bounty on its own site. Researchers who file valid reports and cooperate through remediation will be listed on our research page with their preferred handle. If you would rather stay anonymous, tell us and we will keep it that way.