01How to report
Email security@veizik.com. Korean or English are both fine — our security.txt declares Preferred-Languages: en, ko.
A report we can act on quickly contains:
- Steps to reproduce — the shortest path from nothing to the bug.
- Where — affected URL, API endpoint, or client version (vz --version).
- Impact — what an attacker actually gets, not just what looks anomalous.
- Proof of concept — request/response, script, or a short screen recording.
- How you want to be credited, if you want to be (see §5).
We do not publish a PGP key yet, so please do not encrypt your first message — send it in plain text, and if the finding warrants it we will arrange an encrypted channel with you directly.
Please do not open a public GitHub issue for a security finding — that is disclosure, not a report.
02Scope
In scope — you may test these:
- veizik.com and *.veizik.com.
- The control-plane API at /api/* — signup, licensing, entitlement, session and telemetry endpoints.
- The public status page, status.veizik.com, once it is live.
- The desktop client and engine distribution (veizik / vz), including its update and activation flow.
Out of scope — please do not test these:
- Denial of service — volumetric, stress, or resource-exhaustion testing against production.
- Social engineering of our staff, customers, or vendors; phishing; physical attacks against people, offices, or hardware.
- Third-party platforms we merely use — Cloudflare, our payment merchant-of-record, Google Workspace, GitHub Releases. Report those to that vendor; ask us and we will help you route it.
- Automated scanner output with no demonstrated impact, and missing-header or best-practice findings with no exploit path.
- Attacks that presuppose an already fully compromised device. Veizik runs on the customer's own machine, and our published threat model already concedes that an attacker with root on that machine can reach the local runtime. That is a known, accepted limit — not a new finding.
Anything not listed above: ask at security@veizik.com first rather than assuming. We would much rather answer a question than receive an apology.
03Safe harbor
If you make a good-faith effort to follow this policy, we will:
- consider your research authorized under applicable computer-misuse and anti-hacking law;
- not pursue or support legal action against you for it;
- not seek an injunction against you for good-faith research;
- work with you to understand and resolve the issue quickly.
Good faith means: interact only with accounts you own or have explicit permission to use; avoid privacy violations, data destruction, and degradation of the service for other people; and never access, modify, download, or retain data that is not yours — if you encounter someone else's personal data, stop immediately and tell us. Give us reasonable time to remediate before disclosing publicly (§5).
This is a promise of restraint by us. It is not a waiver of anyone else's rights, and it cannot grant permission that is not ours to give — we cannot, for example, authorize you to test a customer's own systems or a third party's platform.
If a third party takes action against you over research that followed this policy, tell us and we will make clear that your activity was authorized.
04What you can expect from us
These are commitments, measured from when your report reaches security@veizik.com. Business days are Korea Standard Time (KST, UTC+9).
| Stage | Our target |
|---|---|
| Acknowledge receipt | within 2 business days |
| Triage & severity assigned | within 5 business days |
| Status updates | at least every 10 business days, until closed |
| Fix target — Critical / High | 7 / 30 days from triage |
| Fix target — Medium / Low | 90 days / best-effort |
We use CVSS 3.1 as a guide for severity. The final rating is ours, and we will explain it to you rather than simply assert it. If you think we got it wrong, say so — we would rather argue about severity than miss a real one.
05Coordinated disclosure
Our default embargo is 90 days from your report, or until a fix ships — whichever comes first. We will agree a disclosure date with you rather than impose one.
With your permission we will credit you in the acknowledgments below. Tell us the name or handle you want to be listed under, or tell us you would rather stay anonymous. Please do not disclose publicly before the agreed date.
06Rewards
Today this is a recognition-only program: we credit valid, novel reports in the acknowledgments list. We do not currently pay a cash bounty — we would rather say that plainly than imply a reward that does not exist. If that changes, this section changes with it.
07Abuse reports (not vulnerabilities)
Misuse of the product — deepfakes, non-consensual intimate imagery, impersonation, or child sexual abuse material generated with Veizik — is not a vulnerability, and does not go to the security address. Report it to abuse@veizik.com.
Suspected CSAM is escalated immediately on receipt and is handled outside the timelines in §4. If you are reporting imagery of yourself, say so in the subject line and we will prioritize it.
08Acknowledgments
Researchers who have responsibly disclosed a valid issue to us are listed here, with their permission.
No entries yet — this list opens with the first valid report. Be the first.
09Contact
- Vulnerabilities — security@veizik.com
- Product abuse / NCII / CSAM — abuse@veizik.com
- Privacy & data-subject requests — privacy@veizik.com (see the Privacy Policy)
- Everything else — support@veizik.com
- Machine-readable — /.well-known/security.txt (RFC 9116)
Operator: 링크픽 LinkPick (brand: Veizik), Republic of Korea. This policy is governed by the law of the Republic of Korea and is intended to be read alongside our Terms of Service and Privacy Policy; where they conflict, the Terms control.