Security report
security@zonegaze.comSend suspected vulnerabilities, exposed secrets, unsafe agent behavior, or access-control concerns. Include the affected surface, safe reproduction steps, likely impact, and a contact method.
Security
Send vulnerability reports to security@zonegaze.com. Include the affected page, product surface, safe reproduction steps, likely impact, and a safe follow-up contact.
ZoneGaze pages describe workflows where agents can affect real code. Reports that involve agent behavior are most useful when they identify the review step, source material, and exact output that created the risk.
Security report
Use safe reproduction details.
Sensitive data
Do not send secrets or private source.
Current posture
Static launch surfaces with evidence gates.
What to report
Choose the channel that matches the issue. Keep public forms free of secrets, exploit payloads, customer data, and unrelated confidential content.
Send suspected vulnerabilities, exposed secrets, unsafe agent behavior, or access-control concerns. Include the affected surface, safe reproduction steps, likely impact, and a contact method.
Use Downloads to compare posted SHA-256 values before reporting a suspicious DMG, APK, manifest, mirror, or checksum mismatch.
Use support for setup issues, broken documentation links, demo problems, and product questions that do not include confidential material or exploit details.
Use privacy routing for questions about waitlist details, contact records, analytics handling, or requests tied to personal information.
Do not submit passwords, private keys, customer data, proprietary source, or third-party confidential content through public forms or demos.
Sensitive data
Check the Downloads page first. If a DMG, APK, chunked manifest, or mirrored file does not match the published hash, send only safe file metadata and reproduction steps.
Checksum mismatch
artifact URL
SHA-256 shown on /downloads
SHA-256 you computed
Matrix version
Apple Silicon or Intel Mac
download file name
where the file came from
Posture
ZoneGaze Web is a static launch and documentation surface. Public pages are checked for evidence-backed claims, sensitive-data warnings, and links to the right reporting channels before promotion.
Flow materials emphasize review before shipping agent-authored code. Security issues tied to agent output should include the prompt context, affected file, and review step where the risk appeared.
Agent Exchange pages keep trust, source, license, and approval context visible so users can inspect what an agent resource claims before using it.
ZoneGaze does not operate a public bug bounty program right now. Reports are welcome, but testing must stay lawful, minimal, and limited to systems you are authorized to inspect.
Agent workflow risks
Useful reports explain whether the issue came from a prompt, generated patch, dependency recommendation, resource listing, review bypass, or documentation gap.
Review gates for agent-assisted code changes.
Trust and listing context for agent resources.
Route non-sensitive setup and product issues.
Verify the current Matrix Mac preview hashes and signing notes.
For legal, privacy, and product-boundary context, review /privacy and /terms before sending sensitive material.