Security Policy
Last updated: 3 September 2026
Zoundio AB (“Zoundio,” “we,” “our,” or “us”) builds and operates the Gibson App, the websites gibson.app and zoundio.com, and Rechords. We take the security of our users’ accounts and data seriously, and we welcome reports from security researchers who help us find problems before they are abused. This page explains how to reach us, what you can expect back, and the terms under which we will not pursue legal action against you.
This is our coordinated vulnerability disclosure policy for the purposes of Regulation (EU) 2024/2847 (the Cyber Resilience Act).
1. How to Report a Vulnerability
Email us at security@zoundio.com. Please do not open a public issue, post on social media, or share the details anywhere else until we have had a chance to fix the problem.
To help us triage quickly, please include:
- The affected product, URL, endpoint or app version
- Clear, reproducible steps; a short screen recording is ideal
- What an attacker could actually achieve, and how you assess the impact
- Any accounts, IP addresses or user agents you used, so we can match our logs
- How you would like to be credited, if you want to be
Our machine-readable contact details are published at /.well-known/security.txt (RFC 9116).
2. What You Can Expect From Us
- Within 48 hours: we acknowledge your report and confirm we are looking at it. If you have not heard from us in 48 hours, please resend; assume it got lost, not ignored.
- Within 5 business days: we tell you whether we could reproduce the issue, how we assess its severity, and our intended remediation plan.
- Until it is closed: we keep you updated on progress, let you know when a fix ships, and agree public disclosure timing with you.
3. Scope
In scope:
- The Gibson App for iOS (com.berggram.amped) and Android (com.zoundio.amped)
- The websites gibson.app and www.gibson.app, including the web player and practice tools
- The website zoundio.com and www.zoundio.com
- Rechords
- Our public APIs and backend services used by these products
- Account, authentication, subscription and payment flows
Out of scope:
- Denial-of-service and volumetric or stress testing of any kind
- Social engineering, phishing or physical attacks against our staff, users or offices
- Reports from automated scanners with no demonstrated, working impact
- Missing hardening headers or best-practice findings with no exploitable impact
- Vulnerabilities in third-party services we do not operate (report those to their owners)
- Anything requiring a rooted, jailbroken or otherwise compromised device the attacker already controls
4. Rules of Engagement
- Give us a reasonable chance to fix the issue before you tell anyone else. Our default coordination window is 90 days from your first report.
- Use only your own accounts and test data. Do not access, modify or download data belonging to other users.
- Stop as soon as you have confirmed a vulnerability exists. Do not pivot further into our systems.
- Do not exfiltrate data. If you encounter personal data by accident, stop, delete it and tell us in your report.
- Keep your testing within the scope listed above and do not degrade the service for other users.
5. Safe Harbour
If you make a good-faith effort to follow this policy while researching and reporting a vulnerability to us, then:
- We will not initiate or support legal action against you in connection with your research, and we will not report you to law enforcement.
- We consider your research authorised activity under our Terms of Use, and we waive any claim that it breaches them.
- If a third party brings action against you for research that followed this policy, we will make it known that your activity was authorised.
This commitment covers your research, not unrelated activity. It cannot waive the rights of third parties or obligations we owe under Swedish or EU law. If you are unsure whether something is in bounds, email us at security@zoundio.com and ask first.
6. Recognition
We are a small team and we do not currently run a paid bug bounty programme, so please do not expect a monetary reward. What we do offer is a fast, human response, a real fix, and public credit if you want it. We are always happy to confirm your findings in writing for your portfolio or CV.
7. Regulatory Contact
Zoundio AB, Götgatan 34, 118 32 Stockholm, Sweden, is the manufacturer of the Gibson App and Rechords for the purposes of Regulation (EU) 2024/2847 (the Cyber Resilience Act). Enquiries from national authorities, CSIRTs or market surveillance authorities can be sent to security@zoundio.com.
For privacy and personal data questions, see our Privacy Policy. For general enquiries, contact hello@zoundio.com.