Coordinated Disclosure

Vulnerability Disclosure
Policy.

Zoriken operates an open, good-faith coordinated disclosure programme. This page sets out how to reach the security team, what is in scope, and the protections afforded to researchers acting in good faith within this policy.

If you believe you have discovered a vulnerability in any Zoriken-operated system, we welcome a confidential, encrypted report. We commit to acknowledge within seventy-two hours, triage within seven days, and to coordinate publication with the reporter.

Encrypted Contact

Reports should be sent to security@zoriken.com encrypted to the Zoriken Security PGP key. The public key is published at the canonical location below.

PGP Public Key
Fingerprint
PGP_FINGERPRINT_PENDING
The fingerprint is also published on the Trust Centre at /trust.html. Both values must match. A mismatch should itself be reported as a possible publication-tampering incident.

Scope

In scope

Out of scope

Safe Harbour

Zoriken will not initiate, support, or recommend legal action against a researcher whose security research is conducted in good faith and stays within the bounds of this policy. Specifically, if you:

...then your activity is authorised under this policy and we will treat the testing as a good-faith security research engagement. We will further advocate on your behalf to any third party that brings legal action arising from your conduct under this policy. This safe harbour does not waive any third-party rights and does not authorise activity that violates the laws of Trinidad & Tobago, the United Kingdom, or the European Union.

Coordinated Disclosure Timeline

We aim to complete remediation and publication on the following timeline, measured from the date a valid report is received:

For findings that affect a live tenant of a public body, we will additionally notify the commissioning Accounting Officer within seventy-two hours of confirmation, in line with our breach-notification commitment under the Data Protection Act, 2011.

What We Ask of Researchers

Use the encrypted channel
Send the report to security@zoriken.com encrypted to the published PGP key. Plain-text reports will be accepted but the encrypted route is preferred for any finding that exposes credentials, PII, or contract data.
Provide reproducible detail
Include affected URL, HTTP request, expected behaviour, observed behaviour, and timestamps. A clean reproduction shortens triage by days.
Limit data access
Do not access more data than the minimum needed to demonstrate the issue. Do not download, export, or retain client procurement records, personal data, or supplier financial submissions.
Hold publication
Do not publish, blog, tweet, or present the finding before the coordinated publication date. We will work with you on responsible timing and joint announcement if you wish.

What We Will Do

Acknowledge in seventy-two hours
Every valid report receives a written acknowledgement, an internal tracking reference, and the named contact who owns the response.
Triage in seven days
We will assign CVSS 3.1 severity, validate reproducibility, and confirm remediation ownership within seven days of acknowledgement.
Fix on a CVSS-prioritised schedule
Critical: 7 days. High: 30 days. Medium: 60 days. Low: 90 days. Where a fix requires a third-party dependency, we will keep the reporter informed of the blocker.
Credit on consent
With the reporter's written consent, the finding and the reporter's name or handle will be acknowledged on our Hall of Fame. Anonymous credit is also available.

Bounties

Zoriken does not currently operate a paid bounty programme. We are exploring partnership with an established platform; until then, recognition is provided through the Hall of Fame and a written reference letter on company letterhead, available on request.

Variation and Review

This policy is reviewed annually and may be revised in response to a material change in scope, threat landscape, or regulatory requirement. The most recent version is always the canonical version published at /security/policy.html. The version history is available on request.

Last reviewed: April 2026 · Next review: April 2027