Report Security Issues

Last updated: September 8, 2026

If you discover a security vulnerability on petzown.com, please report it to us as soon as possible. We review legitimate security reports and will make reasonable efforts to investigate and resolve confirmed issues quickly.

Before submitting a report, please review the guidelines, eligibility requirements, reward information, and exclusions below.

Responsible Disclosure Guidelines

If you follow these guidelines when researching and reporting a security vulnerability, Pet Zown will not initiate legal action against you in relation to your good-faith security research.

We ask that you:

  1. Give us reasonable time to investigate and resolve the reported issue before sharing it publicly or with another party.
  2. Do not access, modify, download, or delete data belonging to another person without their permission.
  3. Make a good-faith effort to avoid privacy violations, data loss, service interruption, or disruption to our customers.
  4. Do not exploit a vulnerability beyond what is reasonably necessary to demonstrate that it exists.
  5. Do not use social engineering, phishing, physical attacks, denial-of-service attacks, or automated testing that could affect the availability of our services.
  6. Comply with all applicable laws and regulations.

Bug Bounty Programme

We appreciate security researchers who help us protect our customers and services. Pet Zown may offer a monetary reward for eligible reports.

All rewards are issued at our sole discretion and depend on factors including severity, impact, exploitability, report quality, and whether the vulnerability has already been reported.

Eligibility Requirements

To be considered for a reward, you must:

  1. Follow all responsible disclosure guidelines listed above.
  2. Report a genuine vulnerability that creates a meaningful security or privacy risk.
  3. Be the first person to submit a complete and reproducible report of the issue.
  4. Provide clear technical details and step-by-step instructions that allow us to reproduce the vulnerability.
  5. Report any accidental access to personal, confidential, or restricted information immediately.
  6. Keep all information about the vulnerability confidential until we confirm that it may be disclosed.

How to Submit a Report

Please send your security report to:

Email: contact@petzown.com

Please use “Security Vulnerability Report” as the email subject and include:

  • A clear description of the vulnerability
  • The affected page, feature, or URL
  • Step-by-step reproduction instructions
  • The potential security or privacy impact
  • Screenshots, videos, or proof-of-concept information, where helpful
  • Your name and preferred contact details

Please do not contact individual Pet Zown employees about security reports.

Review Process

We investigate valid reports and prioritise them based on severity, impact, and risk. Response and resolution times may vary depending on the complexity of the issue.

Submitting a report does not guarantee a response, reward, or payment. Pet Zown makes the final decision regarding eligibility, severity, and reward value.

Reward Guidelines

The amounts below are the maximum rewards normally available for each severity level. Final reward amounts remain at Pet Zown’s discretion.

Critical Severity — Up to €200

Critical vulnerabilities may allow an attacker to gain full administrative access, execute code remotely, steal funds, or compromise highly sensitive information.

Examples may include:

  • Remote code or command execution
  • Full administrative authentication bypass
  • SQL injection exposing sensitive customer data
  • Complete unauthorised access to customer accounts
  • Vulnerabilities that enable financial theft

High Severity — Up to €100

High-severity vulnerabilities may significantly affect the security of our platform, customers, or internal systems.

Examples may include:

  • Authentication or authorisation bypass
  • Disclosure of sensitive company or customer information
  • Stored cross-site scripting affecting other users
  • Local file inclusion
  • Insecure handling of authentication cookies or sessions

Medium Severity — Up to €50

Medium-severity vulnerabilities may affect multiple users or require limited user interaction.

Examples may include:

  • Security-related business logic flaws
  • Insecure direct object references
  • Unauthorised access to non-critical information

Low Severity

Low-severity issues generally affect individual users and require significant interaction or specific conditions. These reports may be recognised but do not always qualify for a monetary reward.

Examples may include:

  • Open redirects
  • Reflected cross-site scripting with limited impact
  • Low-sensitivity information exposure

Additional Reward Rules

  • Reports must contain enough detail for us to reproduce the issue.
  • For duplicate reports, only the first complete and reproducible report may qualify.
  • Multiple symptoms caused by the same underlying vulnerability will normally receive one reward.
  • Reports describing several unrelated vulnerabilities will be evaluated separately.
  • Pet Zown may change, suspend, or end the programme at any time.

Out-of-Scope Reports

The following issues do not normally qualify for a reward:

  • Issues that require physical access to a device
  • Missing security headers without a demonstrated security impact
  • Clickjacking on pages without sensitive actions
  • Self-XSS or issues that affect only the reporting user
  • Automated scanner reports without manual verification
  • Rate-limit observations without a demonstrated security impact
  • Social engineering, phishing, spam, or physical attacks
  • Denial-of-service or traffic-flooding tests
  • Issues affecting unsupported or outdated browsers
  • Previously reported or publicly known vulnerabilities

Confidentiality and Publication

Do not publicly disclose a vulnerability without our written permission. Pet Zown reserves the right to publish information about resolved security reports where appropriate.

Contact Us

For security-related questions or vulnerability reports, contact:

Email: contact@petzown.com
Telephone: +353 57 912 5548