Thank you for taking an interest in the security of Zenlayer. We value the security of our customers, their data and our services — this page exists so customers, users and security researchers can report any perceived or potential security issue they discover. This form is the company-wide intake for Console, Turbo and every other Zenlayer product, not just Zenlayer Cloud.
Handle the information you share with us in line with our privacy policy.
Treat every researcher who contributes with respect — we appreciate the help keeping our customers safe.
Investigate valid reports and work to remediate them on a timeline appropriate to severity and the systems affected. We may follow up with you for more detail.
We ask that you please
Not disclose details of your submission to third parties without our prior written permission.
Provide as much detail as possible, including clear reproduction steps, so we can validate your report quickly.
Not include confidential or proprietary information belonging to a third party unless you have permission to share it.
Include your email in the submission so we can follow up on any technical details we need.
Out of scope
The following are not covered by this program:
Testing the physical security of our data centers, offices, employees or equipment.
Non-technical attacks such as social engineering or phishing.
DoS/DDoS testing, or anything else intended to disrupt production systems.
Accessing, downloading or modifying data in an account that isn’t yours.
Sending spam or other unsolicited messages as part of testing.
Testing third-party applications or services not operated by Zenlayer.
Defacing or otherwise modifying any Zenlayer asset.