Responsible Disclosure Policy
How to report a security vulnerability in SayNo · SayNo
Effective date: 8 July 2026 · Provided by: XZero Labs Private Limited
1. Our commitment
We value the security research community. If you've found a vulnerability in SayNo or our systems, we want to hear about it and fix it quickly. This policy explains how to report and what you can expect from us.
2. How to report
Email: hello@xzerolabs.com
Include: a description of the issue, the affected app version or endpoint, clear steps to reproduce, and any proof-of-concept. Please don't include third parties' personal data.
Encryption: PGP key for sensitive reports - To be updated.
3. Our commitments to you
Acknowledge your report, typically within 3 working days.
Investigate and keep you reasonably updated on progress.
Fix validated issues as quickly as we responsibly can, based on severity.
Credit you for the discovery if you'd like (and if the fix is public).
4. Safe harbour
Good-faith research is welcome
If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research. Act in good faith, avoid privacy violations and service disruption, and give us reasonable time to fix issues before public disclosure.
5. Please do not
Access, modify or delete data that isn't yours, or degrade our service (no denial-of-service or spam testing).
Use social engineering, phishing, or physical attacks against our staff or users.
Publicly disclose a vulnerability before we've had a reasonable chance to fix it.
6. Scope
In scope: the SayNo Android and iOS apps and [our official domains/endpoints, e.g. *.xzerolabs.com].
Out of scope: third-party services we rely on (report those to the third party), and findings with no realistic security impact.
7. Rewards
Bug bounty: Not yet - To be updated.
Reports are handled on a goodwill basis and thanks/credit is offered
8. The security.txt file
Refer: security


