Security

Report security issues without sending live secrets.

Send vulnerability reports to security@zonegaze.com. Include the affected page, product surface, safe reproduction steps, likely impact, and a safe follow-up contact.

ZoneGaze pages describe workflows where agents can affect real code. Reports that involve agent behavior are most useful when they identify the review step, source material, and exact output that created the risk.

Security report

Use safe reproduction details.

Sensitive data

Do not send secrets or private source.

Current posture

Static launch surfaces with evidence gates.

What to report

Prioritize actionable, reproducible risk.

Choose the channel that matches the issue. Keep public forms free of secrets, exploit payloads, customer data, and unrelated confidential content.

Security report

security@zonegaze.com

Send suspected vulnerabilities, exposed secrets, unsafe agent behavior, or access-control concerns. Include the affected surface, safe reproduction steps, likely impact, and a contact method.

Artifact integrity

/downloads

Use Downloads to compare posted SHA-256 values before reporting a suspicious DMG, APK, manifest, mirror, or checksum mismatch.

Support routing

/support

Use support for setup issues, broken documentation links, demo problems, and product questions that do not include confidential material or exploit details.

Privacy request

/privacy

Use privacy routing for questions about waitlist details, contact records, analytics handling, or requests tied to personal information.

Sensitive data

/terms

Do not submit passwords, private keys, customer data, proprietary source, or third-party confidential content through public forms or demos.

Sensitive data

Keep reports useful and safe.

Check the Downloads page first. If a DMG, APK, chunked manifest, or mirrored file does not match the published hash, send only safe file metadata and reproduction steps.

Checksum mismatch

artifact URL

SHA-256 shown on /downloads

SHA-256 you computed

Matrix version

Apple Silicon or Intel Mac

download file name

where the file came from

Posture

Current posture and boundaries.

Current posture

ZoneGaze Web is a static launch and documentation surface. Public pages are checked for evidence-backed claims, sensitive-data warnings, and links to the right reporting channels before promotion.

Review controls

Flow materials emphasize review before shipping agent-authored code. Security issues tied to agent output should include the prompt context, affected file, and review step where the risk appeared.

Resource provenance

Agent Exchange pages keep trust, source, license, and approval context visible so users can inspect what an agent resource claims before using it.

Not a bug bounty

ZoneGaze does not operate a public bug bounty program right now. Reports are welcome, but testing must stay lawful, minimal, and limited to systems you are authorized to inspect.

Agent workflow risks

Report the agent context, not only the symptom.

Useful reports explain whether the issue came from a prompt, generated patch, dependency recommendation, resource listing, review bypass, or documentation gap.