Zillapi takes the security of its developer API and of our customers’ data seriously. We welcome reports from security researchers, customers, and the public, and we are committed to investigating and resolving valid issues promptly.
Reporting a vulnerability
If you believe you have found a security vulnerability in the Zillapi service, please email us at hello@zillapi.com with the subject line “Security”.
To help us investigate quickly, please include where you can:
- A description of the vulnerability and the affected endpoint, page, or component.
- The steps required to reproduce it, including any request or response details.
- The potential impact as you see it.
- Any proof-of-concept material, screenshots, or logs.
Please do not include real third-party personal data in your report, and please give us a reasonable opportunity to remediate before any public disclosure.
What happens next
- Acknowledgement. We aim to acknowledge your report within two business days.
- Triage. We assess the report, confirm the issue, and assign a severity based on its impact and exploitability.
- Remediation. We prioritise and fix confirmed vulnerabilities, and we will keep you informed of our progress and of when a fix has shipped.
- Recognition. With your permission, we are glad to credit researchers who responsibly disclose valid issues.
Coordinated disclosure to affected customers
If a confirmed vulnerability affects our customers, we notify the affected customers directly — at the contact on their account — with the information they need to understand and respond to it, including:
- A description of the vulnerability;
- The affected product(s) and/or service(s);
- The potential impact;
- The severity of the issue; and
- Guidance on remediation and any action required on the customer’s part.
Routine security patches that require no customer action are applied centrally and take effect for all customers automatically.
Good-faith research
We will not pursue or support legal action against researchers who, in good faith, discover and report a vulnerability in accordance with this policy, provided they avoid privacy violations, degradation of the service for other users, destruction of data, and disruption of our operations. Testing must be limited to accounts you own or have explicit permission to test.
Scope
This policy applies to the Zillapi website (zillapi.com) and the Zillapi developer API. Reports about third-party services we rely on should be directed to the relevant provider, though we are happy to help coordinate where a customer is affected.
Questions about this policy? Contact us at hello@zillapi.com.