Security
How we build, and how to tell us when we got it wrong.
Reporting a vulnerability.
- Contact
- support@
zyg-squared.com - security.txt
-
/.well-known/security.txt - Include
- Affected component, steps to reproduce, impact assessment, and how you’d like to be credited — if at all.
- Acknowledgement
- Within 3 business days.
- Remediation plan
- Within 10 business days for confirmed issues.
- Scope
-
zyg-squared.comand subdomains we operate; published Zyg-Squared LLC iOS and Android applications.Out of scope: third-party services (report to them directly), social engineering, physical testing, denial-of-service, and high-volume automated scanning.
Good-faith research is authorized.
We will not pursue legal action against researchers who make a good-faith effort to avoid privacy violations and service disruption, interact only with accounts they own or have explicit permission to test, and give us a reasonable window to remediate before public disclosure.
The defaults we apply everywhere.
- Infrastructure in Terraform, reviewed via pull request before any apply
- CI/CD deploys via OIDC — no long-lived cloud keys anywhere
- Least-privilege IAM per workload; MFA on all human accounts
- HSTS preload, strict Content Security Policy, modern TLS only
- S3 private by default; CloudFront via Origin Access Control
- Access logs retained 365 days, archived to Glacier after 90
- Pre-commit secret scanning and dependency advisory review
If we discover or are notified of a confirmed incident affecting personal data we process, we notify affected individuals and relevant authorities consistent with the legal obligations of the data’s jurisdiction.