Security and vulnerability disclosure
Last changed 2 October 2026.
How do I report a vulnerability?
Email security@zerocaptcha.io. Say what you found, how to reproduce it, and what an attacker could do with it. A person reads every report, confirms that it arrived, and keeps you told until it is fixed. Please keep the details private until then. The same address is in our security.txt.
What is in scope?
- This site, zerocaptcha.io, with its docs and test pages.
- The dashboard, app.zerocaptcha.io.
- The API, api.zerocaptcha.io, in every format it accepts.
- Our public code and SDKs.
Out of scope: the payment processor's checkout pages, which NOWPayments runs; reports that need a compromised device or browser; missing best-practice headers or cookie flags with no impact you can show; and denial-of-service by volume.
Rules for testing
- Use only accounts you created. Never read, change or delete another customer's data; stop and tell us if you reach any.
- Do not degrade the service for others: no load testing, flooding or automated scans at high rates.
- Solve tasks only against sites you are allowed to test, as the Acceptable Use Policy requires.
- Do not use social engineering or physical attacks, and do not attack our staff or their accounts.
- Top-ups are real payments and final. Test the payment flow with the $10 minimum at most.
Safe harbour
If you act in good faith and follow these rules, we treat your research as authorized: we will not take legal action against you or report you to the authorities for it, and we will say so if anyone else asks. If you are unsure whether something is allowed, ask us first at security@zerocaptcha.io.
Is there a bounty?
No. We do not pay for reports. We will credit you by name when the fix ships, if you want that.
Other questions
For anything that is not a vulnerability, see Contact us. To report a site ZeroCaptcha was used against, use the abuse report form.