Skip to content
ZivoBooks

Product

Responsible Disclosure Policy

How security researchers can report a vulnerability to us safely, and what we promise in return.

Last updated 8 October 2026

Reporting a vulnerability

We welcome reports from security researchers and customers. If you think you’ve found a security problem in Zivobooks, email with:

  • a description of the problem and where it is;
  • the steps to reproduce it, including any proof-of-concept;
  • what an attacker could do with it; and
  • how we can contact you.

What we promise

  • We’ll acknowledge your report within 3 business days.
  • We’ll keep you updated as we investigate and fix it.
  • We won’t take legal action against you for research done in good faith under this policy.
  • With your permission, we’ll thank you publicly once the problem is fixed.

What we ask of you

  • Only test with accounts and businesses you created yourself. Never access, change or delete other customers’ data. If you come across it by accident, stop and tell us.
  • Don’t run denial-of-service attacks, spam, social engineering of our staff or customers, or physical attacks.
  • Don’t use automated scanners in a way that degrades the service for others.
  • Give us reasonable time to fix the problem before telling anyone else about it.

In scope

  • The Zivobooks web application and the customer portal for invoices and quotes.
  • The Zivobooks API and webhooks.
  • This website.

Out of scope: third-party services we integrate with (report those to the provider), findings that need a compromised device, missing best-practice headers with no real impact, and reports generated only by automated tools.

Questions about this document?

Write to . For anything about your personal information, write to .