GzoneSphere — Legal
Responsible Disclosure & Bug Bounty
Found a vulnerability? Here’s how to report it, what’s in scope, and what you can earn.
Last updated · July 12, 2026
01Overview
If you find a security vulnerability in GzoneSphere, we want to hear about it. Report it responsibly and we will reward you.
Report vulnerabilities to security@gzonesphere.com.
02Scope
In scope
- GzoneSphere web application (gzonesphere.com)
- API endpoints
- Mobile applications
Out of scope
- Third-party services (Razorpay, Resend)
- Social engineering attacks on GZS staff
- Physical security
03Rules of Engagement
- Do not access or modify other users’ data.
- Do not disrupt platform availability.
- Do not publicly disclose the vulnerability before we have patched it (90-day disclosure window).
- Do not use automated scanning tools without coordination.
04Reward Tiers
Rewards are subject to severity assessment by our security team.
| Severity | Examples | Reward |
|---|---|---|
| Low | Information disclosure, minor misconfigurations | Public acknowledgment + GZS Pro subscription |
| Medium | XSS, CSRF, privilege escalation | ₹5,000 – ₹25,000 |
| High | SQL injection, RCE, authentication bypass | ₹25,000 – ₹1,00,000 |
| Critical | Full database access, payment system compromise | ₹1,00,000+ (negotiable) |
05Response Timeline
- Acknowledgment within 48 hours.
- Assessment within 7 days.
- Patch deployment within 30 days for critical/high severity, 90 days for medium/low severity.
Questions?
If anything on this page is unclear, reach out at support@gzonesphere.com or through our contact page.
