VerifiedHow we measureHead-to-headTimeMachine StatusWho it's forPricingDocsGet a key
Security

Security & Vulnerability Disclosure

VDP v1.0Last updated: August 9, 2026veizik.com · all subdomains
We welcome good-faith security research. This page is the policy referenced by our security.txt. If you believe you have found a vulnerability, please tell us before you tell the world — write to security@veizik.com and we will work with you. Sections 3 and 4 are our side of the bargain: safe harbor, and response times we hold ourselves to.

01How to report

Email security@veizik.com. Korean or English are both fine — our security.txt declares Preferred-Languages: en, ko.

A report we can act on quickly contains:

  • Steps to reproduce — the shortest path from nothing to the bug.
  • Where — affected URL, API endpoint, or client version (vz --version).
  • Impact — what an attacker actually gets, not just what looks anomalous.
  • Proof of concept — request/response, script, or a short screen recording.
  • How you want to be credited, if you want to be (see §5).

We do not publish a PGP key yet, so please do not encrypt your first message — send it in plain text, and if the finding warrants it we will arrange an encrypted channel with you directly.

Please do not open a public GitHub issue for a security finding — that is disclosure, not a report.

02Scope

In scope — you may test these:

  • veizik.com and *.veizik.com.
  • The control-plane API at /api/* — signup, licensing, entitlement, session and telemetry endpoints.
  • The public status page, status.veizik.com, once it is live.
  • The desktop client and engine distribution (veizik / vz), including its update and activation flow.

Out of scope — please do not test these:

  • Denial of service — volumetric, stress, or resource-exhaustion testing against production.
  • Social engineering of our staff, customers, or vendors; phishing; physical attacks against people, offices, or hardware.
  • Third-party platforms we merely use — Cloudflare, our payment merchant-of-record, Google Workspace, GitHub Releases. Report those to that vendor; ask us and we will help you route it.
  • Automated scanner output with no demonstrated impact, and missing-header or best-practice findings with no exploit path.
  • Attacks that presuppose an already fully compromised device. Veizik runs on the customer's own machine, and our published threat model already concedes that an attacker with root on that machine can reach the local runtime. That is a known, accepted limit — not a new finding.

Anything not listed above: ask at security@veizik.com first rather than assuming. We would much rather answer a question than receive an apology.

03Safe harbor

If you make a good-faith effort to follow this policy, we will:

  • consider your research authorized under applicable computer-misuse and anti-hacking law;
  • not pursue or support legal action against you for it;
  • not seek an injunction against you for good-faith research;
  • work with you to understand and resolve the issue quickly.

Good faith means: interact only with accounts you own or have explicit permission to use; avoid privacy violations, data destruction, and degradation of the service for other people; and never access, modify, download, or retain data that is not yours — if you encounter someone else's personal data, stop immediately and tell us. Give us reasonable time to remediate before disclosing publicly (§5).

This is a promise of restraint by us. It is not a waiver of anyone else's rights, and it cannot grant permission that is not ours to give — we cannot, for example, authorize you to test a customer's own systems or a third party's platform.

If a third party takes action against you over research that followed this policy, tell us and we will make clear that your activity was authorized.

04What you can expect from us

These are commitments, measured from when your report reaches security@veizik.com. Business days are Korea Standard Time (KST, UTC+9).

StageOur target
Acknowledge receiptwithin 2 business days
Triage & severity assignedwithin 5 business days
Status updatesat least every 10 business days, until closed
Fix target — Critical / High7 / 30 days from triage
Fix target — Medium / Low90 days / best-effort

We use CVSS 3.1 as a guide for severity. The final rating is ours, and we will explain it to you rather than simply assert it. If you think we got it wrong, say so — we would rather argue about severity than miss a real one.

05Coordinated disclosure

Our default embargo is 90 days from your report, or until a fix ships — whichever comes first. We will agree a disclosure date with you rather than impose one.

With your permission we will credit you in the acknowledgments below. Tell us the name or handle you want to be listed under, or tell us you would rather stay anonymous. Please do not disclose publicly before the agreed date.

06Rewards

Today this is a recognition-only program: we credit valid, novel reports in the acknowledgments list. We do not currently pay a cash bounty — we would rather say that plainly than imply a reward that does not exist. If that changes, this section changes with it.

07Abuse reports (not vulnerabilities)

Misuse of the product — deepfakes, non-consensual intimate imagery, impersonation, or child sexual abuse material generated with Veizik — is not a vulnerability, and does not go to the security address. Report it to abuse@veizik.com.

Suspected CSAM is escalated immediately on receipt and is handled outside the timelines in §4. If you are reporting imagery of yourself, say so in the subject line and we will prioritize it.

08Acknowledgments

Researchers who have responsibly disclosed a valid issue to us are listed here, with their permission.

No entries yet — this list opens with the first valid report. Be the first.

09Contact

Operator: 링크픽 LinkPick (brand: Veizik), Republic of Korea. This policy is governed by the law of the Republic of Korea and is intended to be read alongside our Terms of Service and Privacy Policy; where they conflict, the Terms control.