Responsible disclosure
Report a security issue
This HTTPS form is ZKAuth’s active public vulnerability channel. It sends through the verified service domain to a private operator destination without exposing that address.
Safe-harbor intent
Good-faith testing against accounts and tenants you control is welcome. Avoid privacy violations, disruption, persistence, social engineering, denial of service, and accessing data that is not yours.
Protect the report
Do not send passwords, API keys, private keys, session tokens, personal data, or live customer records. Attachments are disabled. We can arrange a safer exchange after triage if needed.
Response targets
We target acknowledgement within one business day for critical and high reports, two business days for medium reports, and five business days for low reports. These are targets, not a guarantee of exploitability or bounty payment.
The branded email address security@zkauth.dev is not advertised until inbound DNS routing is configured and tested. The HTTPS channel here is the current canonical contact.