ZOFF LEGAL
Security Policy
This policy explains how to report a potential security vulnerability in Zoff and the rules for good-faith security research.
Last updated: 25 July 2026
Reporting a vulnerability
If you believe you have found a security vulnerability in Zoff, email security@zoff.me. Include a clear description, the affected URL or component, reproducible steps, potential impact, and any supporting evidence that does not expose personal or confidential data.
Please report vulnerabilities privately and allow a reasonable amount of time for investigation and remediation before making information public.
Good-faith research
When investigating or reporting a potential vulnerability:
- Test only accounts, rooms, and data that you own or control.
- Use the minimum interaction needed to demonstrate the issue, and stop once the vulnerability is confirmed.
- Do not access, copy, retain, alter, destroy, or disclose another person's data.
- Do not perform denial-of-service testing, automated high-volume scanning, social engineering, phishing, spam, physical attacks, or attacks against third-party providers.
- Do not disrupt Zoff, bypass rate limits, establish persistence, or use a vulnerability for any purpose beyond reporting it.
Zoff will not pursue action against research performed in good faith and in accordance with this policy. This does not authorize activity that is unlawful, harmful, outside the listed scope, or inconsistent with third-party terms.
Scope
This policy covers the public Zoff service at zoff.me and the open-source Zoff repositories maintained by the Zoff Music organization. Third-party services, music providers, hosting providers, and accounts or systems belonging to other people are outside scope.
No bug bounty
Zoff does not operate a bug-bounty program and does not offer or promise payment, rewards, compensation, gifts, or public recognition for vulnerability reports. Submitting a report does not create a contract or entitlement to compensation.
Response
Zoff will make a reasonable effort to acknowledge actionable reports, investigate them, and keep the reporter informed when practical. Response times and remediation timelines are not guaranteed.