Security
Coordinated disclosure
We welcome reports from security researchers and customers. Good-faith research conducted within these guidelines will not be pursued.
How to report
- 01Email [security@zarryl.com] with the affected asset, reproduction steps and any evidence.
- 02We acknowledge receipt within [x business days] and give you a named contact.
- 03We triage, agree a severity and share a remediation timeline with you.
- 04We confirm the fix and, with your permission, credit your report.
Research guidelines
- Do not access, modify or exfiltrate data that is not yours.
- Do not run denial-of-service, spam or social-engineering tests.
- Give us reasonable time to remediate before any public disclosure.