GetZuga

Vulnerability Disclosure

Version 1.0 · GZ-08-0011 · Last updated 28 August 2026

If you have found a security flaw in GetZuga, we want to hear about it and we will not treat you as a problem for telling us.

Reporting

security@getzuga.com

Please include what you found, how to reproduce it, and what you believe the impact is.

What we commit to

Rewards

We do not offer monetary rewards. We do offer credit.

Said plainly because the alternative is worse: a researcher who assumes a bounty and finds there isn't one has been wasted, and that is how a disclosure turns adversarial.

Please do

Please do not

Out of scope

security.txt

Published at /.well-known/security.txt per RFC 9116.


For the build, not for readers: security.txt must carry Contact: mailto:security@getzuga.com, Policy: https://www.getzuga.com/trust/security, Preferred-Languages: en, and an Expires value computed at build time as publication date plus twelve months. The file is invalid without Expires, and invalid again once it has passed — so the build check should fail if Expires is absent or in the past, rather than only on first publication. /.well-known/ is already exempt from the apex redirect, so the path works today.