Security

How we build, and how to tell us when we got it wrong.

Disclosure

Reporting a vulnerability.

Contact
support@zyg-squared.com
security.txt
/.well-known/security.txt
Include
Affected component, steps to reproduce, impact assessment, and how you’d like to be credited — if at all.
Acknowledgement
Within 3 business days.
Remediation plan
Within 10 business days for confirmed issues.
Scope
zyg-squared.com and subdomains we operate; published Zyg-Squared LLC iOS and Android applications.

Out of scope: third-party services (report to them directly), social engineering, physical testing, denial-of-service, and high-volume automated scanning.

Safe harbor

Good-faith research is authorized.

We will not pursue legal action against researchers who make a good-faith effort to avoid privacy violations and service disruption, interact only with accounts they own or have explicit permission to test, and give us a reasonable window to remediate before public disclosure.

Practices

The defaults we apply everywhere.

  • Infrastructure in Terraform, reviewed via pull request before any apply
  • CI/CD deploys via OIDC — no long-lived cloud keys anywhere
  • Least-privilege IAM per workload; MFA on all human accounts
  • HSTS preload, strict Content Security Policy, modern TLS only
  • S3 private by default; CloudFront via Origin Access Control
  • Access logs retained 365 days, archived to Glacier after 90
  • Pre-commit secret scanning and dependency advisory review

If we discover or are notified of a confirmed incident affecting personal data we process, we notify affected individuals and relevant authorities consistent with the legal obligations of the data’s jurisdiction.