Skip to main content

Security and Responsible Disclosure

Effective: September 8, 2026

Zoninga holds people's financial data, so we take reports seriously and we answer them. This page says how to send one, what happens next, and what is out of scope. It is the policy referenced from /.well-known/security.txt.

1. How to report

Email security@zoninga.com. Plain text is fine. A useful report has:

  • The affected URL, endpoint, or component.
  • Steps to reproduce, with the exact request where that matters.
  • The impact you believe it has, and on whom.
  • Any proof of concept as text. We will not open executables or macro-enabled documents.

Please send the details in the first message. We do not discuss rewards before we have seen a report, and a message that only asks whether we pay will get a reply pointing here.

2. What we promise

  • An acknowledgment within three business days, and a substantive answer within ten.
  • A fix on a timeline that matches the severity, and a note to you when it ships.
  • Credit by name on this page for a confirmed finding, if you want it.
  • A complimentary Premium subscription for a confirmed, previously unknown finding with real impact. The length depends on severity.
  • No legal action against good-faith research that follows the rules below. If you stay within them, we consider your testing authorized under our Terms of Service.

Zoninga does not run a cash bug bounty program. Please don't ask us to make an exception before disclosing; the answer will be this paragraph.

3. Rules for testing

  • Only test against accounts you own. Never read, modify, or delete another user's data. If you stumble onto it, stop, and tell us what you saw and no more.
  • No denial of service, no load testing, no high-volume automated attacks against the live service.
  • No social engineering of Zoninga staff or users, and no phishing.
  • No physical attacks and no attacks on third-party services we use (Plaid, Stripe, Google Cloud). Report their issues to them.
  • Do not publish a finding before we have fixed it or 90 days have passed, whichever comes first. Tell us if you plan to publish and we will coordinate.

4. In scope

The production service at zoninga.com and its API, the MCP endpoints under zoninga.com/mcp, and the AI assistant. We are most interested in anything that exposes one user's financial data to another, bypasses authentication or two-factor, escapes the AI agent's authorization boundaries, or lets a request move or alter money-related records the user did not intend.

5. Out of scope

These are the reports we receive most and they will not earn credit or a reward on their own. Most are automated scanner output without a demonstrated impact.

  • SPF, DKIM, or DMARC configuration, including a policy that is not yet at reject.
  • Missing or "weak" HTTP headers, CSP observations, or cookie flags without a working exploit.
  • Clickjacking on pages that have no sensitive action.
  • Rate limiting, brute-force, or account-lockout reports on endpoints that already have controls, and password-strength policy opinions.
  • User or email enumeration through timing, error wording, or signup responses.
  • Software version disclosure, server banners, and outdated-library reports with no reachable vulnerability.
  • Self-XSS, CSV or formula injection, tabnabbing, open redirects that require user interaction with a link you control.
  • Reports from automated tools submitted without verification.
  • Anything on third-party services, including social media accounts and the payment and bank-connection providers.

If you believe one of these has real impact in our specific setup, show the impact and we will look.

6. Contact

Security reports: security@zoninga.com. Everything else: support@zoninga.com. The machine-readable version of this contact lives at /.well-known/security.txt.