Security & Vulnerability Disclosure

Last updated: June 24, 2026

Zellbox is committed to protecting the security of our users' data. This page is our Vulnerability Disclosure Policy: it gives security researchers clear guidelines for conducting vulnerability-discovery activities against Zellbox and explains how to report vulnerabilities, which systems are in scope, and how long to wait before public disclosure. Zellbox is operated by Blockchain Web Services.

To report a security issue, email security@bws.ninja. We acknowledge reports within three business days.

1. Guidelines

We ask that you:

  • Notify us as soon as possible after you discover a real or potential security issue.
  • Give us a reasonable amount of time to resolve the issue before disclosing it publicly.
  • Make every effort to avoid privacy violations, degradation of the user experience, disruption to production systems, and destruction or manipulation of data.
  • Only use exploits to the extent necessary to confirm a vulnerability's presence. Do not use an exploit to obtain data, establish command-line access or persistence, or pivot to other systems.
  • Once you establish that a vulnerability exists, or encounter any sensitive data (personal data, financial information, or proprietary information of any party), stop your test, notify us immediately, and keep the data strictly confidential.
  • Do not submit a high volume of low-quality reports.

2. Authorization

Security research conducted in good faith and in accordance with this policy is considered authorized. We will work with you to understand and resolve the issue promptly, and Blockchain Web Services will not pursue or support legal action against you in connection with your research.

3. Scope

This policy applies to the following systems and services operated by Zellbox:

  • The Zellbox web application and marketing site at https://zellbox.com
  • The Zellbox API at https://api.zellbox.com

Zellbox is web-only — there is no mobile application or browser extension. Any service not explicitly listed above (including related and third-party services) is out of scope and must not be tested. Vulnerabilities in third-party platforms Zellbox integrates with — Amazon Web Services, Meta / WhatsApp Business Platform, Google, and Stripe — are not covered by this policy and should be reported to the respective vendor under their own disclosure program. If you are unsure whether a system or endpoint is in scope, email security@bws.ninja before you begin.

4. Testing limitations

The following test types are not authorized:

  • Network denial-of-service (DoS or DDoS) testing.
  • Physical testing, social engineering (phishing, vishing), or any other non-technical attack.
  • Automated scanning that generates high request volumes against production without prior coordination.

5. Reporting a vulnerability

Send security reports to security@bws.ninja. We will acknowledge receipt within three business days and keep you updated on our progress. Reports may be submitted anonymously.

6. Information to include

To help us triage and respond, please include:

  • A description of the vulnerability.
  • The location / affected endpoint where it was discovered.
  • The potential impact.
  • Steps to reproduce (including scripts and screenshots where possible).

Please provide your report in English where possible.

7. Our commitment

If you provide contact information, we commit to communicating with you transparently and in a timely manner. We will acknowledge receipt within three business days, keep you informed on confirmation and remediation to the best of our ability, and welcome a dialogue about your findings.