Vulnerability Disclosure Policy
1. Overview
This policy provides a structured process for anyone who wants to report security vulnerabilities in ZAND Bank's systems responsibly, ensuring compliance with industry practices and regional regulations.
2. Purpose
The policy encourages ethical vulnerability reporting to enhance the security of ZAND Bank's website, products, customer data, financial operations and foster collaboration within legal boundaries.
3. Scope
In-scope assets include ZAND Bank's public-facing website (e.g., www.zand.ae and subdomains of *.zand.ae), web portals, systems, APIs, and mobile applications. Security vulnerabilities in these areas impacting confidentiality, integrity, authentication/authorization, or availability qualify for reporting.
3.a. The following are out-of-scope:
| Category | Examples |
|---|---|
| Disruptive Testing | DoS, DDoS, resource exhaustion, spam, request flooding |
| Data Access | Accessing/modifying non-owned data, PII exposure beyond POC, data exfiltration |
| Exploitation | Brute force, credential stuffing, backdoors |
| Passive | Social engineering, phishing, physical access |
| Low Impact | Self XSS, clickjacking, CSRF on anonymous forms, missing security headers, outdated JS libraries, UI bugs, directory listing, or banner grabbing |
| Third party | Third party services that are not owned by ZAND |
| Errors | Error messages without data exposure |
| Best practices | Configuration or features in use that do not have Proof of concept or exploitability |
| Public Keys | Public API keys |
4. Safe Harbor
ZAND Bank considers vulnerability research conducted in good faith, in accordance with this policy, as authorized. ZAND Bank will not pursue legal action against individuals who comply with this policy, applicable UAE laws, and do not exploit vulnerabilities beyond proof-of-concept validation.
5. Guidelines - Do's and DON'Ts
5.a. Do's
- Maintain confidentiality and privacy
- Stop testing immediately upon discovering real customer data/Security vulnerability
- Explain how you found the vulnerability and what the potential impact could be
- Provide detailed description and step-by-step instructions to reproduce with screenshots
- Timeline of testing (Date and Time)
- Submit the report in DOC or PDF format
- Use English language
5.b. Don'ts
- Do not violate confidentiality and/or privacy of Zand's customers and its associates (like users, staff, contractors, systems, etc.)
- Do not engage in actions that could harm ZAND Bank's public image, reputation or trigger negative media attention
- Do not use discovered flaws to query production databases or enumerate user accounts or perform data exfiltration or pivot attacks or further escalation
- Do not publish proof-of-concept exploits, screenshots of sensitive areas, customer information, vulnerability or similar details
- Do not publicly disclose any vulnerability without explicit written authorization from ZAND Bank, following coordinated disclosure timelines agreed by both parties
- Do not disclose or demonstrate vulnerability details on social media, conferences, blogs, or forums (e.g., Reddit, Twitter/X, HackerOne)
- Do not upload vulnerability-related content to non-ZAND platforms
- Do not breach any applicable laws
- Do not use any other methods of communication not described in this policy
- Do not save, copy, retain or archive the ZAND data
- Do not alter or delete information or records
6. Reporting Requirements
Reporters are requested to include technical details of the vulnerability, such as (but not limited to):
- Vulnerability description
- Security Impact
- Affected application
- PoC/Steps to reproduce
- PoC/Exploit code
- Recommendation
- Report directly to Zand via security@zand.ae
- Include your contact details
7. Your personal data
While we encourage you to provide your contact details, doing so is entirely voluntary. Any information you choose to share will be used solely to seek clarification regarding your report, if required. For more information on ZAND's privacy practices, please visit: https://www.zand.ae/en/privacy-policy
8. Protection of data
Ensure that you do not compromise or disclose ZAND's customer information or any other individual's personal information in any form. Any accidental exposure of such data must be reported immediately to security@zand.ae. Failure to adhere to this requirement may result in legal action, as applicable.
Bank Response Timeline
- After the vulnerability has been reported, ZAND will acknowledge the submission within two business days and provide an initial response via email.
- Security researchers may request updates regarding the status of their report no more than once every 15 days. This approach allows the security team to focus on prompt investigation while maintaining open communication.
- Based on the severity and impact of the validated vulnerability, the security team will assign priority levels and determine the necessary remediation actions. Mitigation controls will be implemented to effectively address the security concern.
- Upon remediation, ZAND Bank will formally notify the security researcher of closure, unless restricted by legal or regulatory requirements.
9. Laws, Regulations and Policies
This policy aligns with:
- UAE Cybersecurity Council - National Vulnerability Disclosure Policy
- Federal Decree Law No. 34 of 2021 on Combatting Rumours and Cybercrimes
- CBUAE Cybersecurity and Risk Management expectations
Reference
10. Rewards
ZAND does not currently operate a paid Bug Bounty program. However, we deeply value responsible vulnerability disclosures and welcome anyone who wants to report vulnerabilities they identify. All submissions are carefully reviewed, and contributors are acknowledged by email for their efforts in helping us maintain the security and integrity of our platform.
11. Contact and Updates
If you wish to provide feedback or suggestions on this policy, please contact us through security@zand.ae