Security Policy

Last updated: 3 September 2026

Zoundio AB (“Zoundio,” “we,” “our,” or “us”) builds and operates the Gibson App, the websites gibson.app and zoundio.com, and Rechords. We take the security of our users’ accounts and data seriously, and we welcome reports from security researchers who help us find problems before they are abused. This page explains how to reach us, what you can expect back, and the terms under which we will not pursue legal action against you.

This is our coordinated vulnerability disclosure policy for the purposes of Regulation (EU) 2024/2847 (the Cyber Resilience Act).

1. How to Report a Vulnerability

Email us at security@zoundio.com. Please do not open a public issue, post on social media, or share the details anywhere else until we have had a chance to fix the problem.

To help us triage quickly, please include:

Our machine-readable contact details are published at /.well-known/security.txt (RFC 9116).

2. What You Can Expect From Us

3. Scope

In scope:

Out of scope:

4. Rules of Engagement

  1. Give us a reasonable chance to fix the issue before you tell anyone else. Our default coordination window is 90 days from your first report.
  2. Use only your own accounts and test data. Do not access, modify or download data belonging to other users.
  3. Stop as soon as you have confirmed a vulnerability exists. Do not pivot further into our systems.
  4. Do not exfiltrate data. If you encounter personal data by accident, stop, delete it and tell us in your report.
  5. Keep your testing within the scope listed above and do not degrade the service for other users.

5. Safe Harbour

If you make a good-faith effort to follow this policy while researching and reporting a vulnerability to us, then:

This commitment covers your research, not unrelated activity. It cannot waive the rights of third parties or obligations we owe under Swedish or EU law. If you are unsure whether something is in bounds, email us at security@zoundio.com and ask first.

6. Recognition

We are a small team and we do not currently run a paid bug bounty programme, so please do not expect a monetary reward. What we do offer is a fast, human response, a real fix, and public credit if you want it. We are always happy to confirm your findings in writing for your portfolio or CV.

7. Regulatory Contact

Zoundio AB, Götgatan 34, 118 32 Stockholm, Sweden, is the manufacturer of the Gibson App and Rechords for the purposes of Regulation (EU) 2024/2847 (the Cyber Resilience Act). Enquiries from national authorities, CSIRTs or market surveillance authorities can be sent to security@zoundio.com.

For privacy and personal data questions, see our Privacy Policy. For general enquiries, contact hello@zoundio.com.