← All policies

Zesday Security & Responsible Disclosure Policy

Version: 1.0 Last updated: 14 August 2026

QUBRIX TECHNODE PRIVATE LIMITED welcomes good-faith reports that help protect Zesday customers, restaurants, delivery partners and systems.

1. Reporting

Email support@zesty.in with the subject Security vulnerability report. Include the affected URL, app and version; a clear description; reproducible steps; impact; supporting screenshots or logs with personal data removed; and a safe way to contact you. Do not attach live credentials, full payment data, identity documents or data taken from other users.

We will acknowledge a sufficiently detailed report, triage it by risk and provide updates when reasonably possible. Timelines depend on severity, reproducibility, affected providers and safe deployment. This policy does not promise a bounty or other payment.

2. Good-faith research rules

Use only accounts and data you own or have explicit permission to test. Stop when you encounter another person's data. Use the minimum interaction necessary to demonstrate the issue and give us reasonable time to remediate before public disclosure.

Do not conduct denial-of-service or resource exhaustion; social engineering; phishing; physical intrusion; malware distribution; credential stuffing; destructive testing; automated high-volume scanning; payment, refund or promo abuse; access to restaurant/rider/customer accounts without permission; or modification, deletion, download or retention of third-party data.

3. Out of scope without demonstrated impact

Examples generally include scanner-only reports, missing headers with no exploit, clickjacking on pages with no sensitive action, self-XSS, rate-limit observations that cause no security consequence, outdated component names without a reachable vulnerability, and issues requiring a rooted device or already-compromised account. We may still review them, but they may receive lower priority.

4. Zesday commitments

For research conducted consistently with this policy and applicable law, Zesday will treat the report as good-faith security research and will not intentionally pursue a claim merely for the authorised testing. This is not permission to breach third-party systems or law, and cannot bind regulators or other parties.

5. Customer security

Never share OTPs, passwords, payment credentials or identity documents with an unsolicited caller or message. Zesday support will not ask for your card PIN, CVV or account password. Suspected account compromise or fraud should be reported immediately through the in-app help flow or support@zesty.in.

Version 1. Operated by QUBRIX TECHNODE PRIVATE LIMITED.