Report a Security Vulnerability
Last updated: 20 September 2026
Email [email protected] with "SECURITY" in the subject. Tell us what you found and how to reproduce it. We will confirm we have it within three working days, and we will tell you what we are doing about it rather than going quiet.
Why this page exists
ZeroPercent holds phone numbers, dates of birth, battery history and a record of who someone reached for help, for families that include children. That is a small database with a high consequence if it is wrong, and the people best placed to find a flaw in it do not work here.
A researcher who cannot find a way to tell us has two options: give up, or post it publicly. Both are worse for the families using this app than an email address on a page. So here is the address, and here is what we promise in return.
What we promise
- We will not pursue you. If you act in good faith under the rules below, we will not report you, sue you, or ask anyone else to. That covers the Computer Misuse Act, our terms of service, and anything else we could otherwise point at.
- We will answer. An acknowledgement within three working days, and a decision on whether we are fixing it within ten.
- We will tell you the outcome, including when we decide not to fix something, and why.
- We will credit you when the fix ships, if you want to be credited.
We are a small company and we do not run a paid bounty. We would rather say that plainly than imply a reward that never comes.
The rules
These exist because the accounts on this service belong to families, and a test that goes wrong lands on a real one.
- Do test only against accounts you created yourself.
- Don't access, change or keep anybody else's data. If you reach someone else's record by accident, stop, and tell us what you saw so we can measure the exposure.
- Don't run automated scanners, floods or load tests against the rescue page. It is the page somebody uses on the worst night of their year, and degrading it is the one outcome we cannot accept. Rate-limit yourself.
- Don't send real text messages or place real calls to people who did not agree to it. Our relay reaches actual phones, and someone's mother receiving a test message from a stranger is a harm even when the finding is genuine.
- Don't use social engineering, phishing, or any physical attack on our staff, our suppliers or our offices.
- Do give us a reasonable window to fix it before you publish. Ninety days is our default, and we will ask for longer only with a reason.
In scope
- The ZeroPercent iOS app
zeropercentapp.com, including the rescue, join and member pages- Our API and the edge functions behind it
Out of scope
We will read anything you send, but these are unlikely to get a fix, and saying so up front saves your time as well as ours.
- Reports produced by a scanner with no working proof of exploitation
- Missing headers or weak ciphers with no demonstrated impact
- Rate limiting on endpoints where the limit is deliberate and documented, for instance the rescue throttles
- Anything requiring a jailbroken device, a stolen unlocked phone, or a person's own PIN
- Flaws in Apple, Twilio, Supabase or Cloudflare themselves. Tell them, and tell us so we can respond at our end.
- Social engineering of our team or our users
What to include
The more of this you send, the faster it gets fixed.
- What the flaw lets someone do, in one sentence
- Steps to reproduce it, and the account you used
- The request and response, or a short video
- Your assessment of the impact, and whether you think it is being exploited
If you think it is being exploited right now
Put "SECURITY URGENT" in the subject and say so in the first line. That is read differently from the rest.
If this is not a security flaw
If the app is simply not working for you, the help centre is the faster route. If you have had a suspicious message claiming to be from us, that belongs there too, and it is worth telling us: we will never ask for your Zero PIN, your password or a verification code.