Security & Vulnerability Disclosure
Last updated: June 24, 2026
Zellbox is committed to protecting the security of our users' data. This page is our Vulnerability Disclosure Policy: it gives security researchers clear guidelines for conducting vulnerability-discovery activities against Zellbox and explains how to report vulnerabilities, which systems are in scope, and how long to wait before public disclosure. Zellbox is operated by Blockchain Web Services.
To report a security issue, email security@bws.ninja. We acknowledge reports within three business days.
1. Guidelines
We ask that you:
- Notify us as soon as possible after you discover a real or potential security issue.
- Give us a reasonable amount of time to resolve the issue before disclosing it publicly.
- Make every effort to avoid privacy violations, degradation of the user experience, disruption to production systems, and destruction or manipulation of data.
- Only use exploits to the extent necessary to confirm a vulnerability's presence. Do not use an exploit to obtain data, establish command-line access or persistence, or pivot to other systems.
- Once you establish that a vulnerability exists, or encounter any sensitive data (personal data, financial information, or proprietary information of any party), stop your test, notify us immediately, and keep the data strictly confidential.
- Do not submit a high volume of low-quality reports.
2. Authorization
Security research conducted in good faith and in accordance with this policy is considered authorized. We will work with you to understand and resolve the issue promptly, and Blockchain Web Services will not pursue or support legal action against you in connection with your research.
3. Scope
This policy applies to the following systems and services operated by Zellbox:
- The Zellbox web application and marketing site at
https://zellbox.com - The Zellbox API at
https://api.zellbox.com
Zellbox is web-only — there is no mobile application or browser extension. Any service not explicitly listed above (including related and third-party services) is out of scope and must not be tested. Vulnerabilities in third-party platforms Zellbox integrates with — Amazon Web Services, Meta / WhatsApp Business Platform, Google, and Stripe — are not covered by this policy and should be reported to the respective vendor under their own disclosure program. If you are unsure whether a system or endpoint is in scope, email security@bws.ninja before you begin.
4. Testing limitations
The following test types are not authorized:
- Network denial-of-service (DoS or DDoS) testing.
- Physical testing, social engineering (phishing, vishing), or any other non-technical attack.
- Automated scanning that generates high request volumes against production without prior coordination.
5. Reporting a vulnerability
Send security reports to security@bws.ninja. We will acknowledge receipt within three business days and keep you updated on our progress. Reports may be submitted anonymously.
6. Information to include
To help us triage and respond, please include:
- A description of the vulnerability.
- The location / affected endpoint where it was discovered.
- The potential impact.
- Steps to reproduce (including scripts and screenshots where possible).
Please provide your report in English where possible.
7. Our commitment
If you provide contact information, we commit to communicating with you transparently and in a timely manner. We will acknowledge receipt within three business days, keep you informed on confirmation and remediation to the best of our ability, and welcome a dialogue about your findings.