Contact
Where to report
Do not post a suspected vulnerability in a public issue, social channel, or community chat.
What to include
- the affected URL, feature, or service;
- a clear description of the issue and its likely impact;
- reproduction steps or a minimal proof of concept;
- the date, time, browser, or relevant client version; and
- a safe way to contact you for follow-up.
Remove credentials, personal information, access tokens, and data belonging to others unless they are essential to understanding the report. Ask us to arrange a suitable transfer method before sending sensitive evidence.
Research boundaries
Limit testing to systems operated by Zokor Labs. Do not access, modify, destroy, download, or retain data belonging to another person. Do not use denial-of-service techniques, high-volume scanning, social engineering, spam, physical attacks, or testing against third-party services without authorization. Stop if testing may affect availability or expose data, then report what you observed.
What to expect
We review reports as soon as practical and may ask for clarification. Response and remediation times depend on severity, reproducibility, and the systems involved. We do not currently have a bug bounty program.
