Security and Vulnerability Disclosure Policy
Version 1.3 · Last updated: 20 September 2026
How to report a security vulnerability to Zencra Labs, what is in scope, and how we respond.
1. About this policy
This policy explains how to report a suspected security vulnerability in Zencra Labs to ZENCRA LABS PRIVATE LIMITED, what we ask of people who test our platform, and how we handle the reports we receive. We welcome reports from security researchers, customers, and members of the public.
This policy is about reporting security issues. How we handle personal data is described in our Privacy Policy at /privacy, and the rules for using the platform are in our Terms of Service at /terms and our Acceptable Use Policy at /acceptable-use.
2. How to report a vulnerability
Send security reports to legal@zencralabs.com with the words security report in the subject line. Please do not report security issues through public channels such as social media, the public gallery, or a public code repository, and please do not include the details in a general support request.
If you believe a report contains sensitive information, tell us in your first message and we will agree a secure way to receive the details before you send them.
3. What to include in a report
A useful report usually contains the following:
- The product area or page affected, and the date and time of your testing.
- A clear description of the issue and why you believe it is a security problem.
- The minimum steps needed to reproduce it, with any request or response detail that is relevant.
- What an attacker could realistically achieve, and any conditions that must be true first.
- Any accounts, identifiers, or test data you used, so that we can trace your activity.
Please send one issue per report. If you are unsure whether something is a vulnerability, send it anyway and say that you are unsure.
4. Scope
In scope: the Zencra Labs website and web application on our own domains, and the interfaces they use, where you are testing against your own account and your own data.
Out of scope:
- Systems, services, and accounts that belong to third parties, including our AI, payment, hosting, and communications providers. Report those to the provider concerned.
- Any testing that uses, accesses, modifies, or exposes another person's account, content, or personal data.
- Denial of service, load testing, stress testing, resource exhaustion, and volumetric or automated scanning that degrades the service for others.
- Social engineering, phishing, or physical access attempts directed at our people, our customers, or our suppliers.
- Attempts to obtain credentials, keys, or tokens belonging to anyone other than yourself.
5. What we ask of you
If you are testing our platform, we ask that you:
- Stay within your own account and your own test data, and stop as soon as you have confirmed an issue.
- Access only the minimum information needed to demonstrate the issue, and do not download, retain, or share data that is not yours.
- Do not modify, delete, or degrade anything that does not belong to you.
- Do not use an issue to gain access beyond what is needed to prove it exists.
- Give us a reasonable opportunity to investigate and address the issue before you disclose it publicly, and coordinate any publication with us.
- Comply with applicable law throughout.
If you accidentally access personal data that is not yours, stop immediately, tell us in your report, and delete any copy you hold.
6. What you can expect from us
We aim to acknowledge security reports we receive, to investigate them, and to keep the reporter informed of the outcome where we can. We may ask follow-up questions or ask you to confirm a fix.
We do not publish a fixed response, triage, or remediation timeline, and this policy does not create a commitment to resolve any particular report within any particular period. We prioritise reports by the risk they present.
We are happy to credit reporters who follow this policy when we publish or communicate about a fix, if you would like that and tell us so.
7. Good faith research
If you make a good faith effort to follow this policy, we will treat your research as authorised conduct, we will not pursue or support a civil claim against you in connection with it, and we will not report it to law enforcement in connection with it, except where we are required by law to do so.
This protection applies only to activity that stays within this policy. It does not cover accessing another person's data, extortion or a demand for payment in exchange for withholding a report, degrading the service for other users, or anything unlawful. It does not waive the rights of any third party, and it does not authorise you to test systems that belong to someone else.
8. No bug bounty programme
Zencra Labs does not operate a bug bounty programme and does not offer monetary rewards, swag, or payment for security reports. Submitting a report does not create an expectation of payment.
We do not accept reports that are submitted on the condition of a reward, and we will not negotiate a fee in exchange for the details of an issue.
9. Reports we usually cannot act on
The following are generally not treated as vulnerabilities unless you can show a realistic security impact:
- Output from an automated scanner submitted without analysis or a working reproduction.
- A missing hardening measure, header, or configuration flag with no demonstrated impact.
- Best practice suggestions, version disclosure, or theoretical issues with no exploit path.
- Self-inflicted issues that require the reporter to compromise their own browser, device, or account first.
- Content, moderation, spam, or policy complaints, which should go to our support channel instead.
10. How we protect the platform
We use reasonable technical and organisational measures to protect the platform and the personal data we hold, including access controls, encryption in transit, and rate limiting. We use established infrastructure and service providers, which are listed at /subprocessors.
No system is completely secure, and we do not claim that our platform is. We hold no security certification or third-party audit attestation, and nothing on this page should be read as claiming one. If a personal data breach occurs, we will act in accordance with applicable law, including notifying the relevant authority and affected users where required.
11. Your own account security
If you believe your account has been accessed by someone else, change your password, review the security options in your account settings, and contact us straight away so that we can help. Protecting your password and any additional authentication factor is your responsibility, as set out in our Terms of Service.
We will never ask you for your password. Treat any message that does as fraudulent and report it to us.
12. Contact
Security reports: legal@zencralabs.com. Account security help and suspected fraud: support@zencralabs.com. Questions about how we handle personal data: privacy@zencralabs.com.
Contact
This document is effective from the Last updated date shown above and may be updated from time to time. When we make changes we will revise that date and, where appropriate, notify you through the platform or by email. Continued use of Zencra Labs after an update means you accept the revised version.