Security
Our practices and how to report issues.
Last updated: July 27, 2026
Notice: this document is not finished
The contracting party's details have not been filled in yet, so the fields marked below are placeholders, not real values. Until they are completed, do not rely on this document; write to support@zugo.dev and we will tell you who you are contracting with. Outstanding fields: entity, companyNumber, address, dmcaAgent, dmcaAddress, dmcaPhone, dmcaDirectory.
Our approach
We protect your data with encryption in transit, access controls, and least-privilege practices. Sensitive abuse-prevention signals (IP, device fingerprint) are stored only as salted hashes, never in raw form.
1. Responsible disclosure
If you discover a security vulnerability, please email us and give us reasonable time to fix it before disclosing it publicly. Do not access, modify, or delete data that isn't yours, degrade the Service, or run intrusive automated scans.
2. Scope
The Zugo web app and its APIs. Third-party services (e.g. Supabase, Stripe, Vercel) have their own disclosure programs.
3. What to include
A clear description, steps to reproduce, and the potential impact. We'll acknowledge your report and keep you updated.
4. Contact
Report security issues to support@zugo.dev with "Security" in the subject.
Language
This document is published in English and in Russian. The English version is the controlling version: if the two differ in meaning, the English text governs. The Russian translation is provided so you can read what you are agreeing to, and we will correct any translation error you report to support@zugo.dev.