LEGAL & TRUST
Security & Responsible Disclosure
ZevByte welcomes responsible reports of credible vulnerabilities in ZevByte-controlled public services.
Effective: 2026-08-16 · Last updated: 2026-08-16
Please report privately
Send reproducible details to [email protected]. Include the affected URL or component, impact, steps to reproduce, and any useful timestamps or evidence.
Researcher expectations
- Do not access data belonging to other users.
- Do not perform destructive, denial-of-service, persistence, or social-engineering testing.
- Do not modify or delete production data.
- Stop if sensitive information is encountered and report it privately.
- Provide enough detail for a safe reproduction and remediation review.
Scope and limitations
Scope is limited to ZevByte-controlled public website and service components. Cloudflare, Google, Resend, PayPal, GCash, and other third-party services are not automatically authorized for testing through this policy.
ZevByte does not currently operate a guaranteed paid bug-bounty program. This page is not an absolute legal safe-harbor guarantee; reports are assessed in good faith with a preference for coordinated, non-destructive disclosure.
Security contact: [email protected]