Responsible Disclosure Policy
Zimmic — ZLabs S.R.L., together with its affiliated companies Zimmic LLC and Zimmic E.A.S. — values the work of security researchers who help keep our systems and our customers safe. This policy describes how to report a vulnerability to us in good faith, and what you can expect from us in return.
Good-Faith Security Research
We welcome good-faith research aimed at identifying and reporting security vulnerabilities so they can be fixed. Good-faith research means accessing only what is necessary to demonstrate a vulnerability, avoiding harm to Zimmic, its customers, and third parties, and reporting findings to us promptly and confidentially.
Scope
This policy covers the zimmic.com website and subdomains operated by Zimmic.
Out of scope: customer environments and customer data; systems and services operated by third parties (including third-party platforms Zimmic uses, which have their own disclosure programs); and Zimmic personnel, offices, and physical infrastructure. This policy cannot authorize testing of systems that Zimmic does not own or operate.
Prohibited Testing
- No social engineering, phishing, or impersonation of Zimmic personnel, customers, or partners.
- No denial-of-service testing or any activity that degrades the availability of our services.
- No destructive testing, including deleting, modifying, or corrupting data.
- No accessing, copying, or exfiltrating personal data or customer data. If you encounter such data unintentionally, stop, do not retain or share it, and report it to us immediately.
- No physical attacks against Zimmic offices or infrastructure.
- No spam or unsolicited messages to Zimmic contacts or forms beyond what is needed to demonstrate a finding.
Safe Harbor
Zimmic will not pursue or support legal action against researchers for security research conducted in good faith and in accordance with this policy, to the extent permitted by applicable law and within Zimmic's authority. This policy does not, and cannot, authorize activity on third-party systems or exempt you from laws that apply to you.
How to Report
Report vulnerabilities to security@zimmic.com. Please include:
- A description of the vulnerability and its potential impact.
- The affected URL, endpoint, or component.
- Steps to reproduce the issue, including any relevant request/response details or proof-of-concept material.
- Your contact details, so we can follow up (anonymous reports are accepted, but we will not be able to keep you informed).
What to Expect
We aim to acknowledge your report within a reasonable time and to keep you informed of our progress as appropriate while we investigate and remediate the issue.
We ask that you practice coordinated disclosure: give us a reasonable opportunity to investigate and remediate the vulnerability before any public disclosure, and coordinate the timing and content of any publication with us.
Zimmic does not currently operate a paid bug bounty program and does not offer monetary rewards for vulnerability reports.



