Security Policy
Effective September 16, 2026 · Version 1.0
SiteZeus Services, LLC and its affiliates that own or operate the properties below (together, "SiteZeus") take the security of our products and customer data seriously. We welcome reports from security researchers, customers, partners, and the public, and we are committed to working with you to resolve issues quickly and safely.
This file is SiteZeus's public Vulnerability Disclosure Policy (VDP). It is the governing statement of scope, safe harbor, and disclosure terms for anyone reporting a vulnerability to SiteZeus.
Reporting a vulnerability
Please report security vulnerabilities by email to security@sitezeus.com.
This is a monitored inbox that accepts reports from external senders. Please do not open a public GitHub issue, post on social media, or use a support ticket to report a security vulnerability.
To help us triage quickly, please include:
- The affected property, URL, or endpoint (and the parameter/component, if known).
- A clear description of the vulnerability and its security impact.
- Step-by-step reproduction instructions, with request/response samples, payloads, or a short proof-of-concept.
- Your assessment of severity and any suggested remediation.
- How you would like to be credited (or that you wish to remain anonymous).
Please do not include live customer data or your own sensitive personal data in a report — redact or use synthetic examples where possible.
Our commitment (response targets)
- Acknowledge receipt within 3 business days.
- Initial triage (validity + severity) within 5 business days of acknowledgement.
- Status updates at least every 10 business days until the report is closed.
- Notify you of remediation/closure within 5 business days of the fix deploying.
Scope
In scope — production, internet-facing SiteZeus properties and the APIs served behind them, including https://app.sitezeus.com, https://client.sitezeus.com, https://login.synuma.com, and other production *.sitezeus.com and *.zeus.ai web properties (including zeus.ai itself) and their public API endpoints. SiteZeus-controlled configuration, code, and data hosted on third-party platforms (for example our identity-provider tenant) are in scope; the platform provider's own infrastructure is not — report those to the provider. Testing those tenants is also subject to the platform provider's rules of engagement, which we cannot waive (see Safe harbor).
Vulnerability classes of particular interest include authentication/session flaws, cross-tenant / multi-tenant data-isolation failures, authorization / IDOR / BOLA, injection (SQLi, command, template), SSRF, RCE, exposure of secrets or customer data, and security-impacting business-logic flaws.
Out of scope — systems not owned or operated by SiteZeus; automated-scanner output with no demonstrated exploit; denial-of-service / volumetric testing; social engineering, phishing, or physical attacks; missing security headers, cookie flags, TLS nits, and SPF/DKIM/DMARC without a demonstrated exploit; self-XSS; and non-production, staging, or internal environments (do not test these). Non-production hosts are recognizable by name: any hostname containing -test, -uat, .test., .dev., .staging., or beginning with test., test-, dev., staging., qa., uat., or poc. is out of scope, whatever its apex domain. If you are unsure whether something is in scope, ask at security@sitezeus.com before testing.
Coordinated disclosure
We practice coordinated disclosure. The disclosure window for a report ends at the earlier of:
- the date SiteZeus confirms to you that a fix is deployed, or
- 90 calendar days from the date SiteZeus receives your report. The clock starts on receipt, not on acknowledgement, so a late acknowledgement never extends it.
Please keep the finding confidential until the disclosure window ends. During the window we will work in good faith to remediate and to coordinate the timing, content, and credit of any public disclosure with you. Once the window ends you may publish, whether or not coordination has concluded; we ask (but do not require) that you give us 7 days' notice so we can publish mitigations alongside your write-up. If a fix genuinely needs longer, we may ask you for a short, bounded extension — extensions are by mutual agreement only, never assumed.
Public disclosure before the disclosure window ends, other than a disclosure you have coordinated with us, forfeits the safe harbor below.
Safe harbor
SiteZeus will not pursue or support legal action against, and will treat as authorized, good-faith security research conducted in accordance with this policy. In short: make a good-faith effort to comply with this policy, including its scope and the disclosure window above; do not access, modify, delete, or retain SiteZeus or customer data beyond the minimum needed to demonstrate a finding; do not degrade or disrupt our systems; do not publicly disclose before the disclosure window ends, other than as coordinated with us; and do not violate applicable law.
For research that meets those conditions, SiteZeus will treat your conduct as authorized under SiteZeus's terms of service and under anti-hacking law as it applies to SiteZeus's own systems — including the U.S. Computer Fraud and Abuse Act (CFAA) and the DMCA anti-circumvention provisions — and will not bring, and will not support, a claim against you for it. This is SiteZeus's own commitment: it cannot bind third parties, waive their rights, or authorize conduct that is otherwise unlawful. If you are unsure whether an action is covered, stop and ask at security@sitezeus.com first.
Recognition
SiteZeus operates a Vulnerability Disclosure Program, not a paid public bug bounty; we do not currently offer monetary rewards. For valid, previously-unknown, in-scope reports we will, at your option, credit you by name/handle and provide a written acknowledgement of your contribution.
This file is SiteZeus's public Vulnerability Disclosure Policy and governs external vulnerability reports. SiteZeus maintains an internal operating procedure (severity classification, remediation service levels, and incident handling) that implements this policy; for external reporters, the terms in this file control. The canonical public copy is published at https://www.sitezeus.com/security; this repository copy mirrors it. In-scope properties also publish a machine-readable contact record at /.well-known/security.txt (RFC 9116) — for example https://www.sitezeus.com/.well-known/security.txt and https://app.sitezeus.com/.well-known/security.txt — each naming its own location as canonical and pointing back to this policy. Effective 2026-09-16 · Version 1.0 · Owner: SiteZeus Security. Reviewed at least annually. Contact: security@sitezeus.com.