ZS | Synack

Overview

This Responsible Disclosure Program (the "Program") page is for security researchers interested in reporting application security vulnerabilities. This is intended for application security vulnerabilities only.

Vulnerabilities submitted to the Program through the form provided will be reviewed by Synack, Inc. ("Synack"). Submissions will be reviewed to confirm they are within the Program scope and a valid security issue. If you submit a valid vulnerability, you will be notified after a fix has been issued, and you will have the opportunity to be added to the Acknowledgments page and to disclose the vulnerability. The submission review and validation process is managed exclusively by Synack through their platform and you must follow the Guidelines, Rules of Engagement, and Scope set forth below to participate. All submissions and queries regarding the Program should be submitted through the Submission Form.

Guidelines

In submitting a request, you agree to:

The following web applications are in scope:

Rules of Engagement

Out of Scope – Low Impact Vulnerabilities

The following vulnerabilities are considered too low of an impact to the client and would be marked as Out of Scope if submitted:

Additional specific vulnerability types considered out of scope due to low impact:

Overview

The following terms of use (the "Terms of Use") apply when you view or use a Responsible Disclosure Program hosted by Synack, Inc. ("Synack", "we", "our", "us") on Synack’s websites ( https://www.synack.com, https://www.synack.com/disclosure-policy/, and any related subdomain, collectively, our "Site"). By using our Site, you agree to fully comply with and be bound by the Terms of Use. Please review them carefully. If you do not accept our Terms of Use, do not access and use our Site. If you have already accessed our Site and do not accept our Terms of Use, you should immediately discontinue use of our Site. Synack commits that, if we conclude, in our sole discretion, that a security vulnerability submitted through our Site complies with the Terms of Use, the applicable Scope and Rules of Engagement and the applicable Responsible Disclosure Guidelines, Synack will not bring a private action against you or refer the matter for public inquiry.

Privacy Policy

We respect the privacy of our Site visitors. Please refer to our Privacy Policy which explains how we collect, use, and disclose information that pertains to your privacy. When you access or use our Site, you signify your agreement to this Privacy Policy.

Eligibility Requirements

You agree that you will not under any circumstances:

Suggestions and Feedback

We welcome your feedback and inquiries. If you have any comments or questions, please contact us by sending an email to support@synack.com.

Company Name

ZS

Website

https://www.zs.com/

About

ZS is a management consulting and technology firm that partners with companies to improve life and how we live it. Founded in 1983, ZS has more than 15,000 employees in 40-plus offices worldwide.

Submit a Vuln

Start Here
By submitting a vulnerability to our responsible disclosure program, you agree to the Terms of Use.