Responsible Disclosure Policy
At Zenda Options, we consider the security of our systems a top priority. Despite our care and attention to security, vulnerabilities may still be present. We appreciate the efforts of security researchers who help us identify and address these vulnerabilities responsibly.
Guidelines for Responsible Disclosure
If you believe you've discovered a security vulnerability in our systems, we encourage you to notify us immediately. We will investigate all legitimate reports and do our best to quickly address any vulnerability.
We request that you:
- Report the vulnerability as soon as possible after discovery
- Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our services
- Only interact with accounts you own or with explicit permission from the account holder
- Provide sufficient information to reproduce the vulnerability so we can resolve it as quickly as possible
Reporting Process
To report a vulnerability, please send an email to security@zendaoptions.com with the following information:
- Description of the vulnerability
- Steps to reproduce the issue
- Potential impact of the vulnerability
- Any additional information that might be useful
Our Commitment
When you submit a vulnerability report, we commit to:
- Acknowledge receipt of your report within 48 hours
- Provide an estimated timeframe for addressing the vulnerability
- Notify you when the vulnerability is fixed
- Recognize your contribution if you wish (we're happy to give credit where it's due)
Scope
This policy applies to all Zenda Options systems, including:
- Zenda Options trading platform
- Zenda Options website and subdomains
- Zenda Options mobile applications
- Zenda Options APIs
Out of Scope
The following types of reports are not considered part of this policy:
- Reports of vulnerabilities in third-party applications or websites
- Reports of vulnerabilities in outdated or unsupported browsers or platforms
- Social engineering attacks
- Denial of Service attacks
- Spam or phishing attempts
Legal Safe Harbor
We will not pursue legal action against individuals who submit security vulnerability reports that adhere to this policy. We consider security research conducted under this policy to be:
- Authorized in accordance with the Computer Fraud and Abuse Act
- Exempt from DMCA prohibitions on circumvention
- Exempt from restrictions against unauthorized access under applicable laws
We appreciate your help in keeping Zenda Options and our users safe!