Last updated 16..07.2026
At Zama, we value the work of security researchers and welcome responsible disclosures of security vulnerabilities. Our goal is to work collaboratively with the security community to identify, validate, and remediate vulnerabilities in a way that protects our users and our systems.
This document outlines our Responsible Disclosure Policy, including how to report vulnerabilities, what is considered in scope, and the expectations for researchers participating in our Bug Bounty Program.
All security issues must be reported privately using one of the following channels:
If the vulnerability affects a Zama project hosted on GitHub, you may also report it directly via GitHub Security Advisories on the corresponding repository.
Using GitHub Security Advisories allows for private, coordinated disclosure with maintainers and enables streamlined remediation and publication workflows.
Regardless of the submission channel, we aim to acknowledge receipt of valid reports in a timely manner and will keep researchers informed as the issue is investigated and remediated.
You may report vulnerabilities by email at: security@zama.org
Please include sufficient detail to allow us to understand and reproduce the issue, including:
We consider research conducted in accordance with this policy to be authorized and in good faith. If you follow these guidelines, Zama will not pursue legal action against you for your security research.
By participating, you agree to:
This safe harbor applies only to activities performed within the scope of this policy.
The following activities are strictly prohibited:
Any testing must be limited to what is strictly necessary to demonstrate the vulnerability and must avoid real-world harm.
We are interested in vulnerabilities that have a clear security impact. In-scope issues include, but are not limited to:
Reports are evaluated based on impact, severity, and likelihood of exploitation.
The following issues are generally considered out of scope and are not eligible for rewards:
Zama retains final authority to determine whether a report is in scope.
Eligible vulnerabilities may be rewarded based on:
Reward amounts, if any, are determined on a case-by-case basis. Duplicate reports are rewarded only for the first valid submission.
We support coordinated vulnerability disclosure and will work with researchers to agree on an appropriate timeline for remediation and, if applicable, public disclosure.
Our Bug Bounty Program follows a responsible and ethical security research model, inspired by industry best practices.
By submitting a report, you agree to:
Failure to comply with this code of conduct may result in disqualification from the program.
We appreciate the efforts of the security research community in helping keep Zama and its users safe. Responsible disclosures make a meaningful difference in improving our overall security posture.
For any questions related to this policy, please contact security@zama.org..