BUG BOUNTY PROGRAMME
BUG BOUNTY PROGRAMME
Become a Zetrix security hero! We have a Bug Bounty Programme where you can help us find and fix security issues.
These initiatives aid in identifying security issues prior to malevolent individuals exploiting them, thereby safeguarding individuals’ finances and data from theft.
Zetrix offers rewards (from $ZETRIX 100 to $ZETRIX 10,000) for finding security problems in their system that could hurt their users or business.
These initiatives aid in identifying security issues prior to malevolent individuals exploiting them, thereby safeguarding individuals’ finances and data from theft.
Zetrix offers rewards (from $ZETRIX 100 to $ZETRIX 10,000) for finding security problems in their system that could hurt their users or business.
Earn up to
Severity of Vulnerability
Earn up to
Severity of Vulnerability
Earn up to
Severity of Vulnerability
Earn up to
Severity of Vulnerability
Earn up to
Severity of Vulnerability
Earn up to
Severity of Vulnerability
Flex your coding skills, unearth hidden weaknesses,
and help keep Zetrix strong!
Flex your coding skills, unearth hidden weaknesses, and help keep Zetrix strong!
Security researchers should email details of any suspected vulnerabilities affecting $ZETRIX or its users to disclosures@zetrix.com, and include the following information in their report:
Disclaimer: In regards to the above, please note the following:
If necessary, you may use our PGP public key to encrypt your communication with us.
Reports may be submitted anonymously. Alternatively, a security researcher may provide contact information as well as any preferred communication methods or times of day to communicate, as they see fit.
Zetrix may offer monetary recognition for vulnerability reports that have a significant business impact on our users, products, or services. Rewards for qualifying findings range from $ZETRIX 100 to $ZETRIX 10,000 in appreciation for your help.
Note: $ZETRIX is a Zetrix issued native currency
Eligibility for monetary recognition is determined by calculating the internal severity of a finding against the potential impact to Zetrix and its userbase. We reserve the right, in our sole discretion, to determine vulnerability qualification for a monetary reward. The following rules apply if the issue is deemed to be valid and significant:
Zetrix may offer monetary recognition for vulnerability reports that have a significant business impact on our users, products, or services. Rewards for qualifying findings range from $ZETRIX 100 to $ZETRIX 10,000 in appreciation for your help.
Any service which is not listed here are considered out-of-scope and are not authorized for testing. The scope of the Zetrix system and services covered by this policy will be periodically updated. If vulnerability discovered in third-party asset, the security researcher should report directly to the vendor in accordance with vendor disclosure policy (if any). If a security researcher aren’t sure whether a system is in scope or not, please contact us at disclosures@zetrix.com.
By participating in Zetrix Vulnerability Disclosure Programme (VDP), security researchers agree to adhere with Zetrix Code of Conduct, listed as below:
To report vulnerability, security researcher are required to consider (1) attack scenario/exploitability and the (2) security impact of the bug. Any of the following actions could result in permanent exclusion from the disclosure programme, as well as a criminal and/or legal investigation.
We do not tolerate any behaviors that may negatively damage other Zetrix users’ experiences on our system and services. We accept only manual or semi-manual tests. All findings coming from automated tools or scripts will be considered out of scope.
The following classes of vulnerabilities are of particular interest to us, and are eligible for attribution upon review:
Zetrix will make a best effort to meet the following response targets for security researcher participating in our programme:
* Zetrix calculates severity based on CVSS 3.0, business impact and environment.
Testing activities conducted in accordance with the Zetrix VDP programme regulation are protected by Safe Harbor, meaning we will not initiate legal action against you. However, if you violate the rules, Zetrix retains all other rights and remedies available to it at law, including the rights to seek legal action or law enforcement notice. Security researcher are expected, to comply with all laws applicable to you, and not to disrupt or compromise any data beyond what our VDP programs permit.
Thank you for helping us keep Zetrix’s user and data safe.