Researchers Register

Coordinated disclosures
received with thanks.

Zoriken acknowledges, with consent, the security researchers whose coordinated disclosures have improved the safety of public-sector procurement infrastructure.

Active acknowledgements

Coordinated disclosures are listed below in reverse chronological order. Researchers may elect to be named, listed under a handle, or remain anonymous; we honour the wish at the time of disclosure. Severity reflects CVSS 3.1 at the time of confirmation. Where a finding remains unresolved, only the date of acknowledgement is shown until remediation is complete.

No coordinated disclosures have yet been received.
Be the first — see policy

How to be acknowledged here

Submit a coordinated disclosure under the Zoriken Vulnerability Disclosure Policy. After remediation, the team will ask for your consent to acknowledge you here, and for your preferred name or handle. Acknowledgement is not gated on a paid bounty.

Last reviewed: April 2026