SECURITY
Security & Responsible Disclosure
We build a platform for security people. If you find a hole in it, we want to hear about it, and we'll treat you well.
Zero Day Arena — Security & Responsible DisclosureLast updated 10 October 2026
§01How to report
Email security@zerodayarena.com with a description of the issue, the steps to reproduce it, the affected URL or component, and the impact you believe it has. A proof of concept helps; screenshots and request/response pairs are fine.
Machine-readable contact details are at /.well-known/security.txt.
§02What happens next
- We acknowledge your report within 3 business days.
- We confirm whether it's valid and tell you what we plan to do.
- We keep you updated until it's fixed, and credit you if you'd like to be named.
§03In scope
- zerodayarena.com (this website)
- app.zerodayarena.com (the event platform), using accounts and events you create yourself
§04Out of scope
- Denial-of-service or load testing against production.
- Social engineering, phishing, or physical attacks.
- Accessing, modifying or deleting other people's data or events.
- Challenges inside a live CTF event. Those belong to the event's organizers and players.
- Reports from automated scanners without a demonstrated impact.
§05Safe harbour
If you act in good faith, stay within scope, avoid harm to users and data, and give us reasonable time to fix an issue before disclosing it, we won't pursue legal action against you for your research.
§06How we build
- Per-team flags are derived with HMAC from a server-side key; flags are never stored in plain lists.
- Challenge containers run isolated per team, with resource limits, from first-party images.
- Attack-Defense checkers run sandboxed, with network egress limited to the game network.
- Score events are append-only, and organizer actions are audited.
- This website loads no third-party scripts and sends strict security headers, including a Content Security Policy.