Software Programming Group LLC values responsible reports that help protect GenZOS Customers and systems. This policy describes authorized good-faith research on Provider-controlled GenZOS assets. It does not authorize testing of a Customer application, repository, deployment, data, account, or third-party service without the separate owner's permission.

Scope

In-scope assets are GenZOS domains, APIs, and applications expressly identified by Provider as eligible for testing. If an asset is not clearly Provider-controlled or listed as in scope, contact security@genzos.ai before testing.

Safe-Harbor Conditions

Provider will not recommend or pursue legal action against a researcher for accidental, good-faith violations of this policy when the researcher:

  • acts to improve security and avoids harm;

  • tests only in-scope Provider-controlled assets;

  • uses the researcher's own account and data unless Provider gives written authorization;

  • stops immediately if personal data, Customer Content, credentials, secrets, or confidential information is encountered;

  • does not retain, copy, download, alter, destroy, or disclose data beyond the minimum evidence needed;

  • avoids disruption, persistence, social engineering, physical intrusion, and privacy invasion;

  • reports promptly and allows a reasonable remediation period before disclosure; and

  • complies with law and Provider's written coordination instructions.

This safe-harbor statement does not bind a third party and does not authorize conduct that is unlawful, extortionate, reckless, or intended to harm.

Prohibited Testing

Do not perform denial-of-service or load testing; destructive testing; ransomware or malware deployment; credential stuffing; phishing or social engineering; spam; physical intrusion; employee targeting; data exfiltration; accessing another Customer's project; persistent access; supply-chain compromise; or testing that could affect availability, privacy, integrity, or safety.

Automated scanning must be rate-limited and stopped if it causes errors or degradation. Do not test third-party AI providers, GitHub, Bitbucket, cloud platforms, payment providers, or Customer-managed infrastructure under this policy.

Reporting

Send reports to security@genzos.ai with the subject "GenZos.ai Vulnerability Report." Include:

  • affected asset, endpoint, feature, and environment;

  • vulnerability type and potential impact;

  • clear reproduction steps and a minimal proof of concept;

  • relevant timestamps, request identifiers, screenshots, or logs;

  • whether any data or account was accessed and how it was handled;

  • recommended remediation, if available; and

  • the researcher's preferred contact and disclosure timeline.

Do not send live credentials, private keys, personal data, or unnecessary Customer Content by ordinary email. Ask for a secure transfer method if sensitive evidence is required.

Provider Response

Provider will aim to acknowledge a credible report, assess severity, request clarification where needed, coordinate remediation, and communicate material status. Response and remediation time depend on severity, complexity, third-party dependencies, and operational risk. This policy does not create a guaranteed bounty, payment, service level, or obligation to disclose internal information.

Coordinated Disclosure

Do not publicly disclose a vulnerability until Provider confirms remediation or the parties agree on a disclosure date. Provider may request additional time where a fix involves complex architecture, Customers, or third parties. Provider will not unreasonably delay coordination and may recognize a researcher where desired and legally permissible.

Customer and User Reports

Customers who suspect unauthorized account access, exposed credentials, data loss, or an active incident should contact security@genzos.ai and support@genzos.ai immediately and rotate affected credentials. A vulnerability report is not a substitute for Customer incident-response obligations.

Contact

  • Security: security@genzos.ai

  • Legal: legal@genzos.ai

  • Provider: Software Programming Group LLC

  • Postal address: 5 Independence Way, Suite 300, Princeton, New Jersey 08540, United States