Trust
Responsible Disclosure
Zarire welcomes good-faith reports of security issues that affect the public Zarire website (zarire.com) and other Zarire-operated public web properties.
Last updated: 2026-08-06
This policy explains how to report issues, what information helps, what testing is not allowed, and what reporters should expect.
Reporting expectations
Reports are reviewed in good faith. Zarire does not currently operate a paid bug-bounty program or guarantee acknowledgment, response, or remediation timelines.
How to report
Email security@zarire.com with a clear subject line such as “Security report — zarire.com”.
Do not open public issues that include exploit details in channels that could enable misuse before coordination.
Information to include
Please include as much of the following as you can:
- Affected URL, host, or system
- Description of the issue
- Steps to reproduce
- Potential impact
- Relevant screenshots, logs, or a minimal non-destructive proof of concept
- Your contact information, if you want follow-up
A severity estimate is helpful but optional.
Good-faith research expectations
Researchers should:
- Act in good faith to improve security
- Test only as needed to confirm the issue
- Minimize data access and stop once the issue is demonstrated
- Avoid privacy harm and service disruption
- Allow Zarire a reasonable opportunity to coordinate before public disclosure
- Prefer non-destructive proof techniques
Activities not permitted
The following are not authorized under this policy:
- Denial-of-service testing, including volumetric or resource-exhaustion testing
- Automated high-volume scanning that may degrade service
- Social engineering of Zarire personnel, customers, or partners
- Physical intrusion or physical attacks
- Destructive testing
- Installing persistence mechanisms or malware
- Accessing, modifying, deleting, or retaining third-party data
- Credential stuffing, brute-force credential attacks, or password spraying
- Privacy violations
- Disrupting normal service
- Public disclosure before reasonable coordination
- Testing third-party systems that are not Zarire’s public web properties, unless you have separate authorization
Coordinated disclosure
Zarire asks reporters to coordinate disclosure. Please do not publish exploit details, indicators that enable easy abuse, or private data until Zarire has had a reasonable opportunity to investigate and address the issue, or until Zarire agrees on a disclosure timeline.
If you believe an issue is being actively exploited, say so clearly in your report.
What reporters can expect
- Reports will be reviewed in good faith
- Zarire may ask clarifying questions
- There is no guaranteed acknowledgment, response, or remediation timeline
- Zarire may decline issues that are out of scope, duplicates, or accepted risk
- Credit may be offered at Zarire’s discretion; there is no obligation to publish acknowledgments

