RESPONSIBLE DISCLOSURE POLICY
(Vulnerability Disclosure Policy)

Last Updated: July 15, 2026

This policy safeguards your personal data, uncovers hidden security risks and establishes a secure framework for reporting technical flaws. By collaborating with independent ethical researchers, we proactively defend our platform and strengthen your digital safety.

At QZZON Group, the security of our infrastructure, products and customer data is a top priority. We recognize the invaluable role that independent security researchers play in keeping the digital ecosystem secure.

This Policy outlines our expectations for ethical researchers, defines what systems are in scope, provides instructions for submitting reports and guarantees safe harbor for those who act in good faith.

1. Safe Harbor Commitments
If you conduct security research and disclose vulnerabilities in accordance with this Policy, QZZON Group promises to:

2. Rules of Engagement
To qualify for safe harbor under this policy, you must strictly adhere to the following rules:

You Must (Do)

You Must Not (Do Not)

3. Scope of Testing
In-Scope Systems
The following assets are open for security testing under this framework:

Out-of-Scope Activities
The following systems, properties and attack vectors are strictly prohibited:

4. Reporting Guidelines & Process
How to Submit a Report
Please submit all vulnerability findings directly to our security team via email.

Required Report Contents
To help us prioritize and reproduce your findings efficiently, please ensure your email includes:

  1. Description: A detailed explanation of the vulnerability and its potential security impact.
  2. Location: The exact URL, parameter, API endpoint, or mobile application version affected.
  3. Steps to Reproduce: Clear, sequential text instructions or an explicit, non-destructive Proof of Concept (PoC) script.
  4. Impact Assessment: Your perspective on how a malicious party could exploit this flaw.
  5. Contact Info: Your name, pseudonym, or preferred handle for attribution (anonymous submissions are accepted but make status updates impossible).

5. What to Expect from Us
Once you submit a report, the QZZON Group security team commits to the following timeline:

6. Policy Status Note
This is a Responsible Disclosure Policy focused entirely on responsible reporting and collaboration. It is not a bug bounty program and QZZON Group does not offer cash bounties or financial rewards for unsolicited submissions.

7. Regional Adjustments & Local Law
This information applies globally, but your local statutory rights always take precedence.


© 1999 – 2026 QZZON Group
Legal & Resources
Privacy Statement
Refund & Warranty Policy
Terms of Service
Do Not Sell or Share My Personal Information