
RESPONSIBLE DISCLOSURE POLICY
(Vulnerability Disclosure Policy)
Last Updated: July 15, 2026
This policy safeguards your personal data, uncovers hidden security risks and establishes a secure framework for reporting technical flaws. By collaborating with independent ethical researchers, we proactively defend our platform and strengthen your digital safety.
At QZZON Group, the security of our infrastructure, products and customer data is a top priority. We recognize the invaluable role that independent security researchers play in keeping the digital ecosystem secure.
This Policy outlines our expectations for ethical researchers, defines what systems are in scope, provides instructions for submitting reports and guarantees safe harbor for those who act in good faith.
1. Safe Harbor Commitments
If you conduct security research and disclose vulnerabilities in accordance with this Policy, QZZON Group promises to:
- Authorization: Consider your research authorized and completely lawful.
- No Legal Action: Refrain from initiating or supporting legal action against you (including under data protection or anti-hacking laws).
- Confidentiality: Keep your personal identity strictly confidential unless explicitly authorized by you or required by law.
- Collaboration: Work transparently with you to understand, validate and remediate the issue quickly.
2. Rules of Engagement
To qualify for safe harbor under this policy, you must strictly adhere to the following rules:
You Must (Do)
- Report Immediately: Notify us as soon as possible after discovering a potential security vulnerability.
- Minimize Data Access: Access the absolute minimum amount of data required to create a functional Proof of Concept (PoC).
- Stop on Sensitive Data: Cease all testing and submit your report immediately if you inadvertently encounter any personally identifiable information (PII), proprietary source code, or financial records.
- Maintain Confidentiality: Give QZZON Group a reasonable time-frame to remediate the issue before sharing any details publicly or with third parties.
You Must Not (Do Not)
- No Disruption: Avoid any testing that impacts the availability or performance of our services (e.g., brute-force or resource starvation).
- No Extortion: Do not demand financial compensation or rewards in exchange for disclosing the vulnerability.
- No Data Modification: Do not delete, alter, or corrupt any data belonging to QZZON Group, its partners, or its users.
- No Malware: Do not install backdoors, web shells, or any form of malicious software on our systems.
3. Scope of Testing
In-Scope Systems
The following assets are open for security testing under this framework:
*.qzzon.com(Main corporate domain and all subdomains)- QZZON Group official mobile applications (iOS and Android)
- Core APIs associated with QZZON Group services
Out-of-Scope Activities
The following systems, properties and attack vectors are strictly prohibited:
- SaaS: Any third-party SaaS services used by QZZON Group (e.g., corporate email platforms, HR portals).
- Social Engineering: Phishing, vishing (voice phishing), smishing, or pretexting attacks against QZZON Group employees or customers.
- Physical Attacks: Attempting to breach physical security at QZZON Group offices, data centers, or properties.
- Denial of Service: Launching Distributed Denial of Service (DDoS) or high-intensity automated vulnerability scans.
4. Reporting Guidelines & Process
How to Submit a Report
Please submit all vulnerability findings directly to our security team via email.
- Email: a3priority@gmail.com
Required Report Contents
To help us prioritize and reproduce your findings efficiently, please ensure your email includes:
- Description: A detailed explanation of the vulnerability and its potential security impact.
- Location: The exact URL, parameter, API endpoint, or mobile application version affected.
- Steps to Reproduce: Clear, sequential text instructions or an explicit, non-destructive Proof of Concept (PoC) script.
- Impact Assessment: Your perspective on how a malicious party could exploit this flaw.
- Contact Info: Your name, pseudonym, or preferred handle for attribution (anonymous submissions are accepted but make status updates impossible).
5. What to Expect from Us
Once you submit a report, the QZZON Group security team commits to the following timeline:
- Triage and Acknowledgement: Within 2 business days, we will acknowledge receipt of your report and provide an initial assessment.
- Remediation Target: We aim to address and resolve verified, critical security flaws within 10 business days of confirmation.
- Status Updates: We will update you at major milestones during the remediation process.
- Recognition: If your report is validated and remediated, we will gladly recognize your contribution unless you choose to remain anonymous.
6. Policy Status Note
This is a Responsible Disclosure Policy focused entirely on responsible reporting and collaboration. It is not a bug bounty program and QZZON Group does not offer cash bounties or financial rewards for unsolicited submissions.
7. Regional Adjustments & Local Law
This information applies globally, but your local statutory rights always take precedence.

© 1999 – 2026 QZZON Group
Legal & Resources
Privacy Statement
Refund & Warranty Policy
Terms of Service
Do Not Sell or Share My Personal Information