Software Programming Group LLC values responsible reports that help protect GenZOS Customers and systems. This policy describes authorized good-faith research on Provider-controlled GenZOS assets. It does not authorize testing of a Customer application, repository, deployment, data, account, or third-party service without the separate owner's permission.
Scope
In-scope assets are GenZOS domains, APIs, and applications expressly identified by Provider as eligible for testing. If an asset is not clearly Provider-controlled or listed as in scope, contact security@genzos.ai before testing.
Safe-Harbor Conditions
Provider will not recommend or pursue legal action against a researcher for accidental, good-faith violations of this policy when the researcher:
acts to improve security and avoids harm;
tests only in-scope Provider-controlled assets;
uses the researcher's own account and data unless Provider gives written authorization;
stops immediately if personal data, Customer Content, credentials, secrets, or confidential information is encountered;
does not retain, copy, download, alter, destroy, or disclose data beyond the minimum evidence needed;
avoids disruption, persistence, social engineering, physical intrusion, and privacy invasion;
reports promptly and allows a reasonable remediation period before disclosure; and
complies with law and Provider's written coordination instructions.
This safe-harbor statement does not bind a third party and does not authorize conduct that is unlawful, extortionate, reckless, or intended to harm.
Prohibited Testing
Do not perform denial-of-service or load testing; destructive testing; ransomware or malware deployment; credential stuffing; phishing or social engineering; spam; physical intrusion; employee targeting; data exfiltration; accessing another Customer's project; persistent access; supply-chain compromise; or testing that could affect availability, privacy, integrity, or safety.
Automated scanning must be rate-limited and stopped if it causes errors or degradation. Do not test third-party AI providers, GitHub, Bitbucket, cloud platforms, payment providers, or Customer-managed infrastructure under this policy.
Reporting
Send reports to security@genzos.ai with the subject "GenZos.ai Vulnerability Report." Include:
affected asset, endpoint, feature, and environment;
vulnerability type and potential impact;
clear reproduction steps and a minimal proof of concept;
relevant timestamps, request identifiers, screenshots, or logs;
whether any data or account was accessed and how it was handled;
recommended remediation, if available; and
the researcher's preferred contact and disclosure timeline.
Do not send live credentials, private keys, personal data, or unnecessary Customer Content by ordinary email. Ask for a secure transfer method if sensitive evidence is required.
Provider Response
Provider will aim to acknowledge a credible report, assess severity, request clarification where needed, coordinate remediation, and communicate material status. Response and remediation time depend on severity, complexity, third-party dependencies, and operational risk. This policy does not create a guaranteed bounty, payment, service level, or obligation to disclose internal information.
Coordinated Disclosure
Do not publicly disclose a vulnerability until Provider confirms remediation or the parties agree on a disclosure date. Provider may request additional time where a fix involves complex architecture, Customers, or third parties. Provider will not unreasonably delay coordination and may recognize a researcher where desired and legally permissible.
Customer and User Reports
Customers who suspect unauthorized account access, exposed credentials, data loss, or an active incident should contact security@genzos.ai and support@genzos.ai immediately and rotate affected credentials. A vulnerability report is not a substitute for Customer incident-response obligations.
Contact
Security: security@genzos.ai
Legal: legal@genzos.ai
Provider: Software Programming Group LLC
Postal address: 5 Independence Way, Suite 300, Princeton, New Jersey 08540, United States