Vulnerability Disclosure Policy

Zezenia Online values the work of security researchers. This policy explains how to test our systems safely, report a vulnerability and coordinate its disclosure with us.

Security Contact

Send vulnerability reports to [email protected]. Put "Security vulnerability report" in the subject so we can route it correctly. For sensitive disclosures, a short term PGP, Age or other public key can be provided on request.

Scope

This policy covers supported Zezenia Online software and public services that we operate, including the game client and services under zezeniaonline.com or playzezenia.com.

Third-party services and products that are not operated by us and are not components of Zezenia Online products are outside this policy. However, vulnerabilities in third-party components incorporated into or supplied as part of Zezenia Online software should be reported to us. Where appropriate, we will coordinate with the relevant component vendor or maintainer.

Testing Rules

When you investigate a possible vulnerability:

  • Follow applicable laws and test only for the purpose of reporting a security issue.
  • Use accounts, game characters, items and data that you own, or that you have explicit permission to use.
  • Use only the minimum testing needed to confirm the issue. Stop if you access sensitive data.
  • Do not copy, change, delete or disclose data that is not yours.
  • Do not disrupt our services or degrade the experience of other users. Do not perform denial-of-service, spam, social engineering, physical access or persistence testing.
  • Do not use a vulnerability to access other systems or accounts.

If you are unsure whether a test is safe or in scope, contact us before you continue.

What to Include

Please provide enough detail for us to reproduce and assess the issue:

  • the affected product, service, URL and version;
  • a clear description, impact and reproduction steps;
  • a minimal proof of concept, screenshots or logs, if available;
  • whether the issue is public or appears to be actively exploited;
  • your planned disclosure date, if any

Do not include personal data or secrets that are not needed to explain the issue.

What to Expect

  • We will deal in good faith with reporters who follow this policy.
  • We aim to acknowledge your report within 24 hours.
  • We will investigate the report, may ask for more information and will share significant status changes when practical.
  • We will work to correct confirmed vulnerabilities based on their severity and complexity.
  • We will keep your identity confidential unless you permit us to share it or the law requires disclosure.

Coordinated Disclosure

Please keep the vulnerability confidential while we investigate and correct it. Our standard coordination period is up to 90 days from our receipt of the initial report. We will discuss the disclosure date with you. Active exploitation or serious public risk may require earlier disclosure. A complex fix or dependency on another vendor may require more time.

Following remediation, we may publish a security advisory describing the affected product, vulnerability, impact, severity and available corrective measures. Publication may be delayed where immediate disclosure would create an unreasonable security risk.

Before disclosure, do not publish exploit code, sensitive data or details that would put users at risk. We will not require a non-disclosure agreement as a condition of receiving your report.

Rewards

This is not a bug bounty program. We do not promise payment, in-game items or other rewards.