Vulnerability Disclosure Policy

How to report security vulnerabilities responsibly

Reporting Channels

Primary Channel: Email security vulnerabilities to security@zimax.net

Please include as much detail as possible about the vulnerability, including steps to reproduce, potential impact, and any proof-of-concept code (if applicable).

We prefer encrypted email when possible. You can use our PGP key (available upon request) for sensitive reports.

For urgent issues that require immediate attention, please mark your email as "URGENT" in the subject line and include a brief summary of the severity.

Scope

This disclosure policy applies to the following Zimax Networks products and services:

  • zimax.net - Corporate website and infrastructure
  • secairadar.cloud - Public trust hub and dashboards
  • app.secairadar.cloud - Trust Registry application
  • ctxeco.com - Managed MCP gateway platform
  • api.ctxeco.com - Runtime API endpoints
  • openContextGraph - Open-source GitHub repository (report via GitHub Security Advisories or email)

Out of Scope: Social engineering attacks, physical security, denial of service (DoS) attacks that don't reveal a vulnerability, and issues in third-party services we integrate with (please report those directly to the third party).

Safe Harbor Statement

We provide safe harbor for security researchers who:

  • Act in good faith and follow responsible disclosure practices
  • Do not access or modify data that does not belong to them
  • Do not disrupt our services or impact other users
  • Do not violate any laws or breach any agreements
  • Give us reasonable time to address the vulnerability before public disclosure

We will not pursue legal action against researchers who comply with these guidelines. We appreciate your help in keeping our products and users safe.

Response Timelines

Initial Response

We aim to acknowledge receipt of your report within 48 hours (business days). For urgent issues, we will respond within 24 hours.

Status Updates

We will provide regular status updates at least every 7 days until the vulnerability is resolved or determined to be out of scope.

Remediation

Remediation timelines depend on severity:

  • Critical: Target resolution within 7 days
  • High: Target resolution within 30 days
  • Medium: Target resolution within 90 days
  • Low: Addressed in next regular release cycle

Public Disclosure

We prefer to coordinate public disclosure with researchers. We will work with you to determine an appropriate disclosure timeline that allows for remediation while giving you credit for your work.

Recognition

With your permission, we would like to recognize security researchers who help improve our security posture. Recognition may include:

  • Listing your name (or handle) in our security acknowledgments page
  • Mentioning your contribution in security advisories (if applicable)
  • Providing a letter of recognition for your records

If you prefer to remain anonymous, we will respect that choice.

Bug Bounty Program

We are currently evaluating a formal bug bounty program. For now, we focus on recognition and coordination rather than monetary rewards.

If you're interested in participating in a future bug bounty program, please let us know in your vulnerability report, and we'll keep you informed.