Vulnerability Disclosure Policy | Marketing Dashboards for Agencies | ZapDigits

Summary

ZapDigits takes the security and privacy of our customers and systems seriously. If you discover a security vulnerability in our services, thank you — we want to hear about it. Please follow the instructions below so we can assess and remediate issues quickly and safely.

Important: We do not authorize any testing that is not explicitly pre-approved in writing. Unauthorized testing, exploitation, or access to systems, data, accounts, or infrastructure is strictly prohibited and may result in civil or criminal legal action. ZapDigits does not offer bounties or payments for vulnerability reports.

What we welcome

If you find a potential security issue affecting ZapDigits (websites, applications, services, APIs, infrastructure), please report it to us via the contact channel below. Good-faith reports that follow this policy will be reviewed and acknowledged — we appreciate responsible reporting and will consider public acknowledgement (credit) at the reporter's request.

What we do not permit

Do not perform any of the following without explicit written authorization from us:

If you perform unauthorized testing, you could be subject to legal action. We will not approve or reward unauthorized tests.

Scope

In-scope:

Out-of-scope:

If you're unsure whether a system is in scope, include the target in your report and we'll confirm.

How to report a vulnerability

Email us at: security@zapdigits.com

When reporting, please include:

Optional but helpful:

If you prefer encrypted email, include our PGP public key fingerprint on the report page (or request it via the security@ address).

What to expect from us

Note: these timelines are target goals. If you do not hear back in the windows above, please follow up to the same email address.

Legal & privacy considerations

Acknowledgements & safe harbor

We appreciate responsible disclosure. While we cannot promise legal immunity, we will consider the manner of testing and whether it complied with this policy when deciding how to proceed. We may recognize researchers with public credit if they request it and the disclosure was responsible.

Contact

malith+security@zapdigits.com

For urgent or sensitive reports, indicate "URGENT — SECURITY REPORT" in the subject line.

Changes to this policy

ZapDigits may update this policy from time to time. The "Last updated" date at the top will reflect the latest change.