Security

Disclosure policy

I do independent security research on apps — mobile and web, from one-person side projects to apps with millions of installs. I capture traffic on my own devices, take the clients apart, and report what I find to the people who can fix it.

This page is the standing policy behind that, in both directions: what happens when I report something to you, and what happens when you report something to me.

If I reported something to you

You got an email from me with a technical write-up. Here is what that means, and what does not happen next.

You have 90 days.
Counted from my first email. I publish no details before that date and hand them to no one else in the meantime.
You get everything up front.
Affected endpoints, reproduction steps, evidence, and a concrete fix suggestion. Nothing is held back to make a better story later.
Tell me it is fixed and I will re-test it.
At no cost, and I will say so if I find the fix incomplete. If I got something wrong, I correct it.
Ask for more time and you will usually get it.
A fix genuinely in progress beats a deadline. What does not extend it is silence.
Silence is not a shortcut.
If I hear nothing back, I escalate through CERT/CC rather than shortening the clock. If I cannot find a contact at all, I go through the app store or a CERT. An unreachable developer is not a reason to publish early.

How I test

Constraints I hold to whether or not anyone is watching.

  • Testing happens on my own devices, with my own accounts.
  • If a boundary looks broken, I prove it once. One record, one ID swap, one request. No bulk access, and I do not collect other people’s data.
  • Write tests use benign, reversible markers, never destructive changes.
  • Third-party data I run into is not stored, shared, or reused. Secrets stay redacted in everything I write.
  • Nothing is published before the developer has been notified.

Reporting something to me

In scope: zachi.dev, this blog, shotluma.com, and my public repositories under github.com/realZachi.

Write to me@zachi.dev.
English or German, both fine. Include what you did and what you saw; a rough note beats no note.
I acknowledge within 72 hours.
With a plain answer on whether I consider it a bug and what I intend to do about it.
There is no bounty.
I am one person. What I can offer is a fast answer, credit under your name if you want it, and a note when it ships.
Please stay gentle.
No automated scanners against production, no access to other people’s data, no service degradation. If you need something to test against, ask me and I will set it up.

Machine-readable: /.well-known/security.txt

On your terms instead

Everything above describes what happens when I find something on my own. If you would rather have me look before that, under your scope and with the findings staying yours, I do paid reviews under the same rules.

About the paid reviews