generated: '2026-09-05' method: searched probe: true source: https://www.zayzoon.com/security program: published: true type: security contact contact: security@zayzoon.com contact_source: https://www.zayzoon.com/security policy_url: https://www.zayzoon.com/security bug_bounty: false bounty_platform: null safe_harbor_stated: false response_sla_stated: false security_txt: served: false probed: - url: https://www.zayzoon.com/.well-known/security.txt status: 404 - url: https://zayzoon.com/.well-known/security.txt status: 404 - url: https://api.zayzoon.com/.well-known/security.txt status: 404 - url: https://app.zayzoon.com/.well-known/security.txt status: 404 - url: https://ca.zayzoon.com/.well-known/security.txt status: 404 note: >- ZayZoon publishes a server-rendered security program page that names a reachable security contact (security@zayzoon.com) and describes recurring third-party penetration testing and vulnerability scanning. It does NOT publish a formal coordinated-disclosure policy, safe-harbour language, a response SLA, or an RFC 9116 /.well-known/security.txt on any host. checked: '2026-09-05'