Responsible Disclosure Guidelines and Restrictions
Zeta Global has a responsible disclosure program hosted through Bugcrowd. This program offers a secure channel for independent researchers to report security issues and vulnerabilities to Zeta Global. Bugcrowd manages all communications with the researcher(s) and vets each submission for accuracy and consistency with program policy.
Researchers submitting through this channel can claim their report in Bugcrowd using their Bugcrowd account. This is not required, however; anyone can submit a security vulnerability to Zeta Global through these means.
The following provides the procedures and guidelines for participating in our program:
Participation restrictions:
- Researchers who are current Zeta Global employees, have family members employed by Zeta Global, or are current vendors or employees of vendors used by Zeta Global or any of its subsidiaries.
- Researchers from countries specifically sanctioned by OFAC (Cuba, Iran, Syria, North Korea, or the Crimea region of Ukraine).
- Researchers designated as a Specially Designated National or Blocked Person by the U.S. Department of the Treasury's Office of Foreign Assets Control, or otherwise owned, controlled, or acting on behalf of such a person or entity.
- Individuals otherwise prohibited under U.S. trade or export control laws.
Researchers must:
- Comply with all applicable laws.
- Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data.
- Not copy any data beyond what is needed to support a finding.
- At no time are researchers authorized to disclose personally identifiable information or other sensitive or restricted data outside of the bounty program.
- Only use an exploit to confirm the existence of a vulnerability.
- Researchers must not use an exploit to go beyond proving the vulnerability exists.
- Not use an exploit to compromise or exfiltrate data, establish command-line access and/or persistence, or pivot to other systems, unless specifically authorized by Zeta Global.
- Not conduct any denial-of-service or other attack that degrades performance or user experience.
- Not use social engineering tactics or techniques to identify or further exploit a vulnerability.
- Receive approval from Zeta Global before releasing details of a vulnerability to the general public.
Reporting a Security Vulnerability
The steps below describe how to engage with Zeta Global's external vulnerability disclosure program, and how submissions are triaged and processed.
- Security researchers registered with Bugcrowd may enroll in Zeta Global's private bug bounty program. Researchers may also submit findings to our disclosure program by selecting the relevant product below, or through the responsible disclosure links on the respective product websites.
- Zeta Global targets may be offered through both public and private programs. Public programs are open to all researchers; private programs are open to select researchers only.
- Researchers who identify security vulnerabilities in one of our products should submit a report through the Bugcrowd platform, including the steps or evidence necessary to reproduce and remediate the issue.
Bugcrowd will review the evidence and, if the issue is reproducible, assign a priority ranging from P1 (highest) to P5 (lowest). Triaged issues may be classified into one of the following categories:
- Duplicate: The issue has already been submitted by another researcher. In this case, Bugcrowd will provide feedback through the Bugcrowd platform.
- Unresolved: Issues accepted by Zeta Global are classified as "unresolved" and managed through our internal workflow.
- Won't Fix: Zeta Global accepts the issue but is unable to remediate it. The issue will be marked accordingly in the Bugcrowd platform to prevent future submissions.
- Out of Scope: The issue is identified as out of scope for the program. For submissions determined to be out of scope, Bugcrowd will provide feedback to the submitter.
Bounty Eligibility
Bounty rewards are limited to submissions made via Zeta Global's Private Bug Bounty Programme on Bugcrowd.
Submissions made through the Responsible Vulnerability Disclosure Programme are not eligible for bounty rewards by default. However, Zeta Global may, at its sole discretion, grant a reward (monetary and/or Bugcrowd researcher points) on a case-by-case basis, based on factors such as the vulnerability's severity and potential impact. To be considered for such an exception, you must claim your submission in Bugcrowd.