1. Reporting a vulnerability
If you believe you have found a security vulnerability in Zoff, email security@zoff.me. Include a clear description, the affected URL or component, reproducible steps, potential impact, and any supporting evidence that does not expose personal or confidential data.
Please report vulnerabilities privately and allow a reasonable amount of time for investigation and remediation before making information public.
2. Good-faith research
When investigating or reporting a potential vulnerability:
- Test only accounts, rooms, and data that you own or control.
- Use the minimum interaction needed to demonstrate the issue, and stop once the vulnerability is confirmed.
- Do not access, copy, retain, alter, destroy, or disclose another person's data.
- Do not perform denial-of-service testing, automated high-volume scanning, social engineering, phishing, spam, physical attacks, or attacks against third-party providers.
- Do not disrupt Zoff, bypass rate limits, establish persistence, or use a vulnerability for any purpose beyond reporting it.
Zoff will not pursue action against research performed in good faith and in accordance with this policy. This does not authorize activity that is unlawful, harmful, outside the listed scope, or inconsistent with third-party terms.
3. Scope
This policy covers the public Zoff service at zoff.me and the open-source Zoff repositories maintained by the Zoff Music organization. This includes Music and Watch rooms, their chat and playback controls, and Zoff's embed, remote, and Cast interfaces. Third-party services, media providers, hosting providers, and accounts or systems belonging to other people are outside scope.
When reporting a room issue, include its Music or Watch type and whether it affects room permissions, provider restrictions, shared playback, or data visibility. Use a room you control and avoid including other participants' messages or personal information.
4. No bug bounty
Zoff does not operate a bug-bounty program and does not offer or promise payment, rewards, compensation, gifts, or public recognition for vulnerability reports. Submitting a report does not create a contract or entitlement to compensation.
5. Response
Zoff will make a reasonable effort to acknowledge actionable reports, investigate them, and keep the reporter informed when practical. Response times and remediation timelines are not guaranteed.
