Zonelytix legal
Responsible disclosure
Version 1.1 · Last updated
Members trust Zonelytix with their settings, their trade history and the keys that let software trade on their accounts. If you find a way to break that trust, we want to hear about it first, and we will treat you fairly for telling us.
Contents
1. In short
- Email security@zonelytix.com. We acknowledge within 2 business days.
- Test only your own accounts, do not access other members’ data, do not disrupt the Service, and give us reasonable time to fix before you publish.
- If you follow these rules we will not take legal action against you, and we will credit you if you want.
This policy is also published in machine-readable form at /.well-known/security.txt.
2. How to report
Send an email to security@zonelytix.com with: the affected URL, endpoint, app or EA version; steps to reproduce, with a proof of concept where possible; the impact as you understand it; and how you would like to be credited, if at all. Please send one issue per report. If the report contains sensitive data, ask for our PGP key in a first message and we will reply with it. Do not report security issues on the public feedback board, on Telegram or on social media.
3. In scope
- zonelytix.com and every subdomain we operate, including the web app and the API.
- The Telegram bot.
- The Zonelytix Bridge Expert Advisor and the EA endpoints, including licence validation and the integrity of reports.
- Outgoing webhooks and their signatures.
- Our open-source repositories, where published.
We are most interested in: access to another member’s data or settings; anything that lets someone place, change or block trades on an account they do not control; licence key forgery or plan bypass; payment or entitlement manipulation; reward or vote manipulation that automated checks miss; authentication and session flaws; server-side request forgery, injection and remote code execution.
4. Out of scope
- Denial of service, rate-limit testing beyond a handful of requests, and anything that degrades the Service for others.
- Social engineering of staff or members, phishing, and physical attacks.
- Vulnerabilities in third-party services we use (Supabase, Whop, Telegram, Resend, cloud hosting, MetaTrader, brokers); report those to the vendor, and tell us too if they affect our members.
- Findings that require a compromised device, browser extension or man-in-the-middle position.
- Reports from automated scanners without a demonstrated impact; missing best-practice headers, SPF or DMARC records without a working exploit; clickjacking on pages with no sensitive action; self-XSS; outdated library versions without a working exploit; content spoofing; open redirects without a security impact.
- The trading logic itself: a losing signal, a disagreement with a zone score or a strategy weakness is feedback, not a vulnerability. Post it on the feedback board.
5. Rules for testing
- Test only against accounts you own. Create free accounts for testing; use the demo EA licence from your own dashboard, never a key belonging to someone else.
- If you encounter another member’s data, stop, do not download or store it, and tell us what you saw.
- Do not modify or delete data that is not yours, do not place or alter trades on any account you do not control, and do not interact with real reward payouts.
- Do not run automated scanners at high rates, do not spam the bot, and do not attempt to exhaust API or AI quotas.
- Do not extort, threaten or demand payment as a condition of disclosure.
- Keep the issue confidential until we have fixed it and agreed on disclosure, or 90 days have passed, whichever is earlier, unless we ask for and you agree to a short extension for a hard fix.
- Comply with the law where you are. This policy cannot authorise testing against third parties.
6. What we promise
- Acknowledge your report within 2 business days and tell you who is handling it.
- Give you an initial assessment of severity and a target fix date within 10 business days.
- Keep you informed as we work on it and tell you when it is fixed.
- Not share your identity without your permission.
- Credit you on this page, if you wish, once the issue is resolved.
7. Safe harbour
If you make a good-faith effort to follow this policy, we consider your research authorised, we will not bring or support legal action against you for it, we will not refer it to law enforcement, we will waive any restriction in the Terms of service that would otherwise prohibit it, and we will work with you if a third party raises a claim about research done under this policy. If you are unsure whether something is covered, ask first. This safe harbour does not cover conduct outside the rules above, and it cannot bind third parties.
8. Our process and timelines
We triage by impact on members’ money, data and ability to trade. Critical issues, such as unauthorised trade placement or cross-account data access, are fixed as an emergency, usually within days, and may involve temporarily disabling a feature and telling affected members. High issues are targeted within 30 days, medium within 60 and low within 90. If a fix will take longer, we tell you why and agree a disclosure date. Where a vulnerability led to a personal data breach, the notification process in the Privacy policy applies.
9. Recognition
We do not currently run a paid bounty programme. We thank researchers who report valid issues here, with their name or handle and a link if they wish, and we may offer plan time or merchandise at our discretion. If a paid programme opens, this page will say so and set out the rules.