Security is foundational to ZishanHack. We welcome responsible security research conducted in good faith and are committed to reviewing all legitimate vulnerability reports promptly.
✓ In Scope
✗ Out of Scope
If you comply with this policy and conduct testing in good faith within scope, we will not pursue legal action for your security research.
Submit all vulnerability reports to:
Acknowledgement target: Within 5 business days
ZishanHack does not operate a paid bug bounty program. Vulnerability reports are accepted for responsible disclosure purposes only.
Qualifying researchers may be recognized in our Security Hall of Fame at our discretion.
We publicly recognize researchers who responsibly disclose valid security vulnerabilities in compliance with this policy.
Hall of Fame inclusion requires: valid non-duplicate vulnerability, full policy compliance, and no premature disclosure.
Public disclosure is permitted only after we have provided written confirmation that the vulnerability has been fully remediated. We request coordinated disclosure to protect our users and infrastructure.
© 2026 ZishanHack. All rights reserved.