specification: API Commons VulnerabilityDisclosure specificationVersion: '0.1' provider: Zayo Group Holdings providerId: zayo-group generated: '2026-09-06' method: searched probe: true source: https://www.zayo.com/security/ http_status: 200 description: >- Zayo Group publishes a full, named Vulnerability Disclosure Policy on its own domain, with scope, expectations, commitments and an explicit safe-harbour clause. Reports are taken through a third-party platform (Inspectiv), not by email. There is no /.well-known/security.txt on any Zayo host, so the policy is discoverable only by browsing the site. policy: published: true title: Zayo Group Vulnerability Disclosure Policy url: https://www.zayo.com/security/ submission_url: https://client.inspectiv.com/vdp/zayo-group/submit-report platform: Inspectiv bug_bounty: false bug_bounty_note: >- Nothing on the page offers a monetary reward. It is a disclosure programme, not a bounty. scope: Any digital assets owned, operated, or maintained by Zayo Group. out_of_scope: >- Vulnerabilities in systems not owned by Zayo should be reported to the appropriate vendor or applicable authority. safe_harbor: true safe_harbor_terms: - Authorized with respect to applicable anti-hacking laws; Zayo will not initiate or support legal action for accidental, good-faith violations. - Authorized with respect to anti-circumvention laws; no claim for circumvention of technology controls. - Exempt from Terms of Service / Acceptable Use Policy restrictions that would interfere with security research, waived on a limited basis. - Considered lawful and conducted in good faith; if a third party initiates legal action, Zayo will make it known the research complied with the policy. - Applies only to legal claims under the control of Zayo; it does not bind independent third parties. disclosure_window_days: 180 disclosure_window_note: >- Zayo asks for "a reasonable amount of time (at least 180 days from the initial report) to resolve the issue before you disclose it publicly". provider_commitments: - Respond to your report promptly, and work with you to understand and validate it. - Keep you informed about the progress of a vulnerability as it is processed. - Work to remediate discovered vulnerabilities in a timely manner, within operational constraints. - Extend safe harbor for vulnerability research related to this policy. researcher_expectations: - Follow this policy and any other relevant agreements; this policy prevails on conflict. - Report any vulnerability discovered promptly. - Avoid violating others' privacy, disrupting systems, destroying data, or harming user experience. - Use only the Official Channels to discuss vulnerability information with Zayo. - Test only in-scope systems. - Limit data access to the minimum needed for a proof of concept; stop and report immediately on encountering PII, PHI, card data or proprietary information. - Interact only with test accounts you own or have explicit permission to use. - Do not engage in extortion. security_txt: served: false evidence: >- /.well-known/security.txt returns 404 on zayo.com, www.zayo.com, developer.zayo.com and trust.zayo.com, and 403 (AWS API Gateway "Missing Authentication Token") on api.zayo.com and auth.api.zayo.com. Probed 2026-09-06; see well-known/zayo-group-well-known.yml. gap: >- A machine cannot find this policy. Zayo has done the hard part — a real policy with safe harbour — and skipped the one line of discoverability that would let a scanner or an agent locate it. Publishing /.well-known/security.txt with Policy: https://www.zayo.com/security/ and Contact: https://client.inspectiv.com/vdp/zayo-group/submit-report would close it. evidence: - url: https://www.zayo.com/security/ status: 200 kind: disclosure policy fetched: '2026-09-06' keywords: - Vulnerability Disclosure Policy - Safe Harbor - Systems in Scope - Official Channels - 180 days - url: https://client.inspectiv.com/vdp/zayo-group/submit-report status: 200 kind: submission portal note: Linked from the policy page as the Official Channel; hosted by Inspectiv, not Zayo. - url: https://www.zayo.com/.well-known/security.txt status: 404 kind: absent maintainers: - FN: Kin Lane email: kin@apievangelist.com