Security documentation

Responsible disclosure

Report a security issue

This HTTPS form is ZKAuth’s active public vulnerability channel. It sends through the verified service domain to a private operator destination without exposing that address.

Safe-harbor intent

Good-faith testing against accounts and tenants you control is welcome. Avoid privacy violations, disruption, persistence, social engineering, denial of service, and accessing data that is not yours.

Protect the report

Do not send passwords, API keys, private keys, session tokens, personal data, or live customer records. Attachments are disabled. We can arrange a safer exchange after triage if needed.

Response targets

We target acknowledgement within one business day for critical and high reports, two business days for medium reports, and five business days for low reports. These are targets, not a guarantee of exploitability or bounty payment.

The branded email address security@zkauth.dev is not advertised until inbound DNS routing is configured and tested. The HTTPS channel here is the current canonical contact.

Used only to discuss this report.

A short, specific title without secret material.

Optional. Do not place tokens, credentials, or customer identifiers in the URL.

30-10,000 characters. Use test tenants and redact secrets, personal data, and live customer content. Attachments are intentionally disabled.