Security Policy
Last updated August 2026.
This page describes how ZeyWeb approaches security and how you can report vulnerabilities responsibly.
Responsible disclosure
If you believe you have found a security vulnerability in our website or services, please report it to us privately through our contact page before disclosing it publicly. Give us reasonable time to investigate and address the issue. Do not access, modify, or delete data that is not yours, and do not disrupt our services while testing.
What to include in a report
- A clear description of the issue and where you found it
- Steps to reproduce it, where possible
- Any supporting evidence, without exposing sensitive data unnecessarily
Data protection basics
We use reasonable technical and organisational measures to protect the data we handle, including access controls, secure handling of credentials, and activity logging. We follow the principle of least privilege and use temporary, scoped access when working on client systems.
Credential handling
We never ask for passwords or secret keys through public forms. Access to client systems is temporary, limited to what is needed, removed when work is complete, and logged.
Contact
To report a security concern, reach us through our contact page and mark your message as security-related.
If you have questions about this document, please contact ZeyWeb.