This document is published in English, and the English text is the one that applies. If anything is unclear, write to us and we will explain it in your language.
Reporting a vulnerability
We welcome reports from security researchers and customers. If you think you’ve found a security problem in Zivobooks, email with:
- a description of the problem and where it is;
- the steps to reproduce it, including any proof-of-concept;
- what an attacker could do with it; and
- how we can contact you.
What we promise
- We’ll acknowledge your report within 3 business days.
- We’ll keep you updated as we investigate and fix it.
- We won’t take legal action against you for research done in good faith under this policy.
- With your permission, we’ll thank you publicly once the problem is fixed.
What we ask of you
- Only test with accounts and businesses you created yourself. Never access, change or delete other customers’ data. If you come across it by accident, stop and tell us.
- Don’t run denial-of-service attacks, spam, social engineering of our staff or customers, or physical attacks.
- Don’t use automated scanners in a way that degrades the service for others.
- Give us reasonable time to fix the problem before telling anyone else about it.
In scope
- The Zivobooks web application and the customer portal for invoices and quotes.
- The Zivobooks API and webhooks.
- This website.
Out of scope: third-party services we integrate with (report those to the provider), findings that need a compromised device, missing best-practice headers with no real impact, and reports generated only by automated tools.