generated: '2026-08-29' method: searched source: https://www.zyte.com/terms-policies/responsible-disclosure-program/ provider: Zyte providerId: zyte program: name: Responsible Disclosure Program (BugHunt) url: https://www.zyte.com/terms-policies/responsible-disclosure-program/ http_status: 200 platform: self-hosted third_party_platform: none note: >- Not on HackerOne, Bugcrowd or Intigriti — Zyte runs the program itself through a form on the policy page. Notably it is NOT advertised via an RFC 9116 /.well-known/security.txt on any Zyte host (see well-known/zyte-well-known.yml), so a machine looking for the program the standard way will not find it. rewards: monetary: false statement: >- "At this time, Zyte does not offer financial rewards for the disclosure of security vulnerabilities." recognition: Security Researcher Hall of Fame, published on the same page with researcher consent. response_commitments: acknowledgement: within 24 hours triage: up to 5 days notification: Zyte notifies the reporter when the issue is fixed. scope: domains: - zyte.com - app.zyte.com - storage.zyte.com note: >- api.zyte.com and docs.zyte.com are not named in the published in-scope list. qualifying: - Remote code execution (RCE) - SQL/XXE injection and command injection - Cross-site scripting (XSS) - Server-side request forgery (SSRF) - Misconfiguration issues on servers and application - Authentication and authorization related issues - Cross-site request forgery (CSRF) non_qualifying: - HTML injection and self-XSS - Host header and banner grabbing issues - Automated tool scan reports (web, SSL/TLS, Nmap) - Missing HTTP security headers and cookie flags on insensitive cookies - Rate limiting, brute force attack - Login/logout CSRF - Unrestricted file upload - Open redirections - Formula/CSV injection - Vulnerabilities requiring physical access to the victim machine - User enumeration (email, user ID) - Phishing / spam, including SPF/DKIM/DMARC issues - Vulnerabilities found in third-party services - EXIF data not stripped on images researcher_obligations: - Only interact with accounts you own or have explicit permission to test. - Perform research only within the published scope. - Do not publish vulnerability details publicly. - Keep information confidential until the issue is resolved. report_contents_required: - Vulnerability overview — description and potential impact - Reproduction steps and proof of concept, video POC where available - Researcher recognition details (name/handle and link) if Hall of Fame inclusion is wanted