Skip to main content

LEGAL & TRUST

Security & Responsible Disclosure

ZevByte welcomes responsible reports of credible vulnerabilities in ZevByte-controlled public services.

Effective: 2026-08-16 · Last updated: 2026-08-16

Please report privately

Send reproducible details to [email protected]. Include the affected URL or component, impact, steps to reproduce, and any useful timestamps or evidence.

Researcher expectations

  • Do not access data belonging to other users.
  • Do not perform destructive, denial-of-service, persistence, or social-engineering testing.
  • Do not modify or delete production data.
  • Stop if sensitive information is encountered and report it privately.
  • Provide enough detail for a safe reproduction and remediation review.

Scope and limitations

Scope is limited to ZevByte-controlled public website and service components. Cloudflare, Google, Resend, PayPal, GCash, and other third-party services are not automatically authorized for testing through this policy.

ZevByte does not currently operate a guaranteed paid bug-bounty program. This page is not an absolute legal safe-harbor guarantee; reports are assessed in good faith with a preference for coordinated, non-destructive disclosure.

Security contact: [email protected]