Security
Disclosure policy
I do independent security research on apps — mobile and web, from one-person side projects to apps with millions of installs. I capture traffic on my own devices, take the clients apart, and report what I find to the people who can fix it.
This page is the standing policy behind that, in both directions: what happens when I report something to you, and what happens when you report something to me.
If I reported something to you
You got an email from me with a technical write-up. Here is what that means, and what does not happen next.
- You have 90 days.
- Counted from my first email. I publish no details before that date and hand them to no one else in the meantime.
- You get everything up front.
- Affected endpoints, reproduction steps, evidence, and a concrete fix suggestion. Nothing is held back to make a better story later.
- Tell me it is fixed and I will re-test it.
- At no cost, and I will say so if I find the fix incomplete. If I got something wrong, I correct it.
- Ask for more time and you will usually get it.
- A fix genuinely in progress beats a deadline. What does not extend it is silence.
- Silence is not a shortcut.
- If I hear nothing back, I escalate through CERT/CC rather than shortening the clock. If I cannot find a contact at all, I go through the app store or a CERT. An unreachable developer is not a reason to publish early.
How I test
Constraints I hold to whether or not anyone is watching.
- Testing happens on my own devices, with my own accounts.
- If a boundary looks broken, I prove it once. One record, one ID swap, one request. No bulk access, and I do not collect other people’s data.
- Write tests use benign, reversible markers, never destructive changes.
- Third-party data I run into is not stored, shared, or reused. Secrets stay redacted in everything I write.
- Nothing is published before the developer has been notified.
Reporting something to me
In scope: zachi.dev, this blog, shotluma.com, and my public repositories under github.com/realZachi.
- Write to me@zachi.dev.
- English or German, both fine. Include what you did and what you saw; a rough note beats no note.
- I acknowledge within 72 hours.
- With a plain answer on whether I consider it a bug and what I intend to do about it.
- There is no bounty.
- I am one person. What I can offer is a fast answer, credit under your name if you want it, and a note when it ships.
- Please stay gentle.
- No automated scanners against production, no access to other people’s data, no service degradation. If you need something to test against, ask me and I will set it up.
Machine-readable: /.well-known/security.txt
On your terms instead
Everything above describes what happens when I find something on my own. If you would rather have me look before that, under your scope and with the findings staying yours, I do paid reviews under the same rules.
About the paid reviews