Policy
Responsible Disclosure
In plain language: If you find a security flaw in my website and you're acting in good faith, I authorize your research, I won't sue you, and I won't report you. Tell me what you found at security@zoevin.io and I'll answer within three business days.
Machine-readable version: https://zoevin.io/.well-known/security.txt
Last updated: 1 August 2026
Why I have this page
I'm going to spend my working life asking small businesses to let a stranger test their systems. It would be strange to ask for that and then leave researchers guessing about whether poking my own site gets them a lawyer letter.
The terms below adopt the disclose.io Core Terms — the closest thing the field has to a common safe-harbor standard — written here in plain English with identical intent.
This page is a commitment I'm making, not legal advice to you. If you're weighing legal risk in your own situation, talk to your own attorney.
Safe harbor
Four promises. They apply to good-faith research on the in-scope assets listed below, conducted within the rules on this page.
1. You're authorized under anti-hacking law
I consider good-faith security research on my in-scope assets to be authorized access. That's the operative word under the federal Computer Fraud and Abuse Act and under California Penal Code § 502, and I'm granting it here in advance.
I won't bring a civil claim against you for that research, and I won't refer it to law enforcement.
2. DMCA anti-circumvention exemption
If your good-faith research involves circumventing a technological measure protecting my site or its content, I grant you an exemption for that purpose. I won't bring a claim under Section 1201 of the Digital Millennium Copyright Act, and I won't ask anyone else to bring one.
3. My own terms are waived while you research
To whatever extent my Terms of Service or any acceptable-use language would otherwise prohibit what you're doing, I waive it for good-faith security research within this policy.
You don't have to choose between following my terms and finding the flaw. The waiver is limited to the research itself, and it lasts as long as you're operating inside this policy.
4. Good faith is acknowledged
If you follow this policy, I'll treat your research as authorized and conducted in good faith, and I'll say so in writing if you need it.
Should a third party bring an action against you over research covered here, I'll make it publicly known that your activity was authorized by me and compliant with this policy.
Good faith is judged by conduct, not outcome. If you accidentally cross a line while genuinely trying to stay inside it, stop, tell me, and we're fine. This protection doesn't extend to extortion, to deliberate damage, or to threatening disclosure in exchange for money.
What's in scope
- zoevin.io and all of its subdomains
- The public web application and any API it exposes
- DNS configuration for zoevin.io
- Email security configuration for zoevin.io — SPF, DKIM, DMARC, and how they're enforced
- The TLS configuration and certificate handling on those hosts
If you're unsure whether something belongs to me, ask at security@zoevin.io before testing it.
Third-party services are out of scope. My hosting provider, my DNS provider, my email delivery provider, and any other vendor infrastructure belong to them. Report those to the vendor under their own policy. If you think a vendor issue is caused by how I configured it, that part is mine and I want to hear about it.
What's out of scope
These aren't covered by the safe harbor above. No hard feelings, but don't do them.
- Denial of service. No DoS, no DDoS, no volumetric or stress testing, no resource exhaustion.
- Automated scanning that degrades the site. Keep request rates reasonable and stop if you see errors. A scanner left running overnight against a small site isn't research.
- Social engineering. Not me, not anyone connected to me, not my vendors. No phishing, no pretexting, no vishing, no smishing, no help desk manipulation, no physical impersonation.
- Physical attacks. No entry to any premises, no tampering with hardware, no dumpster diving.
- Attacks on people. No targeting my personal accounts, my family, my other projects, or anyone who's contacted me.
- Anything destructive. No deleting data, no defacing, no persistence, no installing anything, no ransomware simulation.
- Other people's data. If you reach personal information belonging to someone else, stop right there, don't download it, and tell me immediately.
- Spam or content injection into forms, and testing that fills my inbox.
Reports I'll acknowledge but generally close without action:
- Missing security headers with no demonstrated impact
- Raw scanner output with no working proof of concept
- Clickjacking on pages with no sensitive action
- Self-XSS with no realistic delivery path
- Issues only reproducible on end-of-life browsers
- Software version disclosure with no exploitable path
- Best-practice suggestions without a security consequence
- Findings that require an already-compromised device or a person acting against their own interest
Show me the impact and I'll take almost anything seriously.
How to report
Email security@zoevin.io. Plain email is fine. There's no portal, no account to create, and no form.
What helps me reproduce it fast:
- The affected URL, host, or endpoint
- The vulnerability class and clear reproduction steps
- A working proof of concept, redacted where it needs to be
- What an attacker gets out of it
- Screenshots or a short video if that's easier than writing it up
- Your name or handle as you want it credited, or a note that you'd rather stay anonymous
- The date and time you tested, with a time zone, so I can match your traffic in the logs
Use the minimum access needed to prove the finding. Stop as soon as you've proved it. Don't pivot, don't persist, and don't collect data you don't need.
No PGP key is published yet. If you have something genuinely sensitive to send, email me and we'll arrange an encrypted channel before you send details.
What I commit to
- Acknowledgment within 3 business days. From a human, which in this case is the only human there is.
- A triage decision within 10 business days — whether I've reproduced it, how I'm rating it, and what I plan to do.
- Status updates every 7 days until it's resolved or I've explained why it won't be.
- A reason if I won't fix it. If I'm not going to fix something, I'll tell you why rather than going quiet.
- Credit if you want it. Your name or handle goes in the acknowledgments below, on your terms. If you'd rather stay anonymous, that's respected.
- Coordinated disclosure. Please hold public disclosure for 90 days or until it's fixed, whichever comes first. If I need longer, I'll ask and give you a reason. If I've gone silent past the windows above, publish. That's fair.
No bug bounty. There's no money, because this is a one-person consultancy with no bounty budget and I'd rather say that plainly than run a program I can't fund. What I can offer is a fast human response, public credit, and a written statement of authorization if you ever need one.
Acknowledgments
Researchers who've reported valid findings and wanted credit will be listed here.
Nobody yet. This site is new. Be first.
Next step
Report something
Acknowledged within 3 business days. Safe harbor applies from the moment you start, under the terms above.
Zoevin is a sole proprietorship operated by Chris Bounds in Roseville, California. No separate corporation or LLC is registered for Zoevin today.
- Phone: Email is the contact of record until a phone number is published here.
- Mail: Mailing address is provided on engagement letters when required.
This is not legal advice.