Reporting a vulnerability
We welcome reports from security researchers and customers. If you think you’ve found a security problem in Zivobooks, email with:
- a description of the problem and where it is;
- the steps to reproduce it, including any proof-of-concept;
- what an attacker could do with it; and
- how we can contact you.
What we promise
- We’ll acknowledge your report within 3 business days.
- We’ll keep you updated as we investigate and fix it.
- We won’t take legal action against you for research done in good faith under this policy.
- With your permission, we’ll thank you publicly once the problem is fixed.
What we ask of you
- Only test with accounts and businesses you created yourself. Never access, change or delete other customers’ data. If you come across it by accident, stop and tell us.
- Don’t run denial-of-service attacks, spam, social engineering of our staff or customers, or physical attacks.
- Don’t use automated scanners in a way that degrades the service for others.
- Give us reasonable time to fix the problem before telling anyone else about it.
In scope
- The Zivobooks web application and the customer portal for invoices and quotes.
- The Zivobooks API and webhooks.
- This website.
Out of scope: third-party services we integrate with (report those to the provider), findings that need a compromised device, missing best-practice headers with no real impact, and reports generated only by automated tools.