Legal
Report a vulnerability
Last updated October 2026
We welcome reports from security researchers. If you believe you have found a vulnerability in Zyberon, please tell us, so that we can fix it before anyone is harmed.
01How to report
Email security@zyberon.ai with a description of the issue, the steps to reproduce it, the affected address or component, and the impact you expect. Screenshots or a short proof of concept help. Our machine readable contact details are in security.txt.
You can write in English or Dutch. Please include no personal data of other people beyond what is needed to show the issue.
02What you can expect from us
We confirm that we received your report within three business days, and we give you a first assessment within ten business days.
We keep you informed while we work on a fix and tell you when it is resolved. We aim to fix critical issues within 7 days and serious issues within 30 days.
With your permission, we credit you by name once the issue is fixed. We do not run a paid bug bounty program at this time.
03Guidelines for testing
- Test only against accounts and workspaces that you own, or that you created for testing.
- Do not access, change or delete data that belongs to others. If you come across personal data or customer data, stop, keep no copy, and tell us.
- Do not degrade the Service: no denial of service, no load testing, no spam and no high volume automated scanning.
- Do not use social engineering, phishing or physical attacks against our staff, our customers or our providers.
- Give us reasonable time to fix the issue before you disclose it publicly. We ask for 90 days, or less once a fix is live.
04Scope
In scope: zyberon.ai and its subdomains, the Zyberon dashboard and its APIs, the funnels and tracking endpoints we host for stores, and our Shopify app.
Out of scope: services operated by third parties (such as Shopify, Meta or our sub-processors), findings from automated tools without a demonstrated impact, missing best practices without a concrete risk, and issues that require an already compromised device or account.
05Safe harbor
If you act in good faith and follow this policy, we consider your research authorized, we will not take legal action against you, and we will not report you to the authorities for it. If a third party takes action against you, we will make clear that your research was authorized under this policy.
06How we protect data
Annex III of our Data Processing Agreement describes the technical and organizational measures we apply, and our sub-processor page lists the providers that process data for us.
Questions about this document? Email hello@zyberon.ai.