Report a security concern
Security reports help us protect zapIQ customers, users, and connected services. Use the private channel below for a suspected vulnerability, security incident, exposed credential, or unexpected access.
Private reporting channel
Email security@zapiq.in with the subject “Private security report”. If that address is unavailable, email contact@zapiq.in.
Please do not include secrets, passwords, private keys, access tokens, OAuth tokens, payment-card details, bank credentials, or unnecessary personal data. Tell us how to reproduce the issue without sending live credentials.
What to include
- The affected page, API, integration, or service.
- A concise description of the observed behaviour and potential impact.
- Reproduction steps using non-sensitive test data.
- The approximate date and time observed, including time zone.
- A safe way to contact you for follow-up.
Responsible testing
Do not disrupt service, access another person’s data, change or delete data, use social engineering, attempt physical intrusion, perform denial-of-service testing, or retain data beyond what is necessary to report the issue. Stop testing and report immediately if you encounter personal data, credentials, or customer information.
This page does not authorize access to any system or data. We do not currently operate a public bug-bounty programme.
What happens next
We route security reports to a restricted response process, assess severity and scope, preserve relevant evidence, and coordinate remediation and notifications where required. We may ask for clarification or a safe proof of concept. We will not ask you to send a password, private key, access token, OAuth token, CVV, OTP, or bank credential.
Company
ZAP PRIVATE LIMITED
No. 10, 8th B Cross Road
HAL III Stage, Jeevanbhimanagar
Bengaluru, Karnataka 560075, India
General enquiries: contact@zapiq.in