If you believe you have discovered a vulnerability in any Zoriken-operated system, we welcome a confidential, encrypted report. We commit to acknowledge within seventy-two hours, triage within seven days, and to coordinate publication with the reporter.
Encrypted Contact
Reports should be sent to security@zoriken.com encrypted to the Zoriken Security PGP key. The public key is published at the canonical location below.
Scope
In scope
zoriken.comand any subdomain ending in.zoriken.com- The PRIVI 2.0 application domains operated by Zoriken on behalf of public bodies
- Authentication, session management, and authorisation flows on those domains
- Public endpoints including the OCDS transparency feed and supplier portal
- Third-party libraries delivered by us (server-side or in-browser) where the vulnerability exists in our usage of the library
Out of scope
- Vulnerabilities in third-party infrastructure providers (Vercel, Supabase, Resend, Cloudflare) — please report those to the respective vendor; we will coordinate where helpful
- Social-engineering attacks against Zoriken staff, clients, or contractors
- Physical attacks, theft, or unauthorised entry to facilities
- Denial-of-service testing, traffic flooding, brute-force credential stuffing
- Findings limited to outdated browsers, missing best-practice headers without exploit, or self-XSS without privilege escalation
- Reports generated solely by automated scanners without manual validation
Safe Harbour
Zoriken will not initiate, support, or recommend legal action against a researcher whose security research is conducted in good faith and stays within the bounds of this policy. Specifically, if you:
- Operate strictly within the in-scope assets listed above
- Make a good-faith effort to avoid privacy violations, service disruption, or destruction of data
- Do not exfiltrate data beyond the minimum required to demonstrate the vulnerability
- Do not disclose the vulnerability publicly before the coordinated publication date agreed with us
- Do not extort, defame, threaten, or attempt to leverage the finding for personal gain other than agreed bounty or public credit
...then your activity is authorised under this policy and we will treat the testing as a good-faith security research engagement. We will further advocate on your behalf to any third party that brings legal action arising from your conduct under this policy. This safe harbour does not waive any third-party rights and does not authorise activity that violates the laws of Trinidad & Tobago, the United Kingdom, or the European Union.
Coordinated Disclosure Timeline
We aim to complete remediation and publication on the following timeline, measured from the date a valid report is received:
- 0 to 72 hours — written acknowledgement to the reporter, assignment of an internal tracking reference
- 0 to 7 days — triage complete, severity assigned per CVSS 3.1, remediation owner identified
- 7 to 90 days — remediation deployed, regression test added, reporter notified of fix
- By 90 days from fix, or 180 days from initial report (whichever is sooner) — coordinated public disclosure
For findings that affect a live tenant of a public body, we will additionally notify the commissioning Accounting Officer within seventy-two hours of confirmation, in line with our breach-notification commitment under the Data Protection Act, 2011.
What We Ask of Researchers
What We Will Do
Bounties
Zoriken does not currently operate a paid bounty programme. We are exploring partnership with an established platform; until then, recognition is provided through the Hall of Fame and a written reference letter on company letterhead, available on request.
Variation and Review
This policy is reviewed annually and may be revised in response to a material change in scope, threat landscape, or regulatory requirement. The most recent version is always the canonical version published at /security/policy.html. The version history is available on request.
Last reviewed: April 2026 · Next review: April 2027