Security

Security & Vulnerability Reporting

Security issues and potential vulnerabilities affecting TestZombie AI can be reported to us directly and confidentially.

Last updated: September 2026

Report a vulnerability

Please report suspected or confirmed security vulnerabilities directly to security@testzombie.ai. This address is our central point of contact for product security and vulnerability reports.

Please do not publicly disclose technical details of an unresolved vulnerability before we have had a reasonable opportunity to review the report and provide appropriate remediation.

What to include

Detailed reports help us assess issues more quickly. Where possible, please include:

  • the affected TestZombie product or component and version
  • a clear description of the vulnerability
  • steps to reproduce the issue or a proof of concept
  • the expected impact and your assessment of the risk
  • relevant logs, screenshots or technical details, provided they do not contain unnecessary personal data or secrets
  • a way to contact you for follow-up questions

Coordinated vulnerability disclosure

We support responsible and coordinated vulnerability disclosure. Security reports are reviewed, prioritised and, where an issue is confirmed, handled through our existing development and update process.

  • avoid destructive testing, denial-of-service attacks and unnecessary disruption of systems
  • do not access data belonging to other users or customers and do not modify or delete third-party data
  • use only the data and access necessary to demonstrate the vulnerability in a reproducible manner
  • allow us reasonable time to investigate and remediate an issue before public disclosure

Security updates

Confirmed security issues are handled based on risk. Where remediation requires a product update, we provide the security fix through the release and update channels applicable to the relevant product and publish security information in an appropriate form where required.

EU Cyber Resilience Act

TestZombie takes into account the requirements of Regulation (EU) 2024/2847 (Cyber Resilience Act) and maintains processes for receiving, assessing and handling security and vulnerability reports. Cases meeting statutory reporting criteria are handled under the applicable reporting procedures. This page does not constitute a declaration of full CRA conformity or CE conformity.

Security contact

TestZombie AI / QA Agile OOD
Verila 5
1463 Sofia, Bulgaria

Security: security@testzombie.ai
General support: support@testzombie.ai
Website: testzombie.ai