Security
Operator: Zookzy AI Technologies (Pvt) Ltd, brand "Zookzy".
This page summarises security practices in general terms. It does not create contractual warranties beyond those expressly stated in the Terms of Service. You accept that no online service can provide absolute protection.
1. Overall security approach
We build Zookzy as a layered system: encrypted channels, application access controls, network segmentation, event monitoring, and human review of high-risk content.
However: no organisational or technical measure eliminates the possibility of an incident. If personal data are compromised, we act in accordance with the Privacy Policy and applicable law, but we are not liable for losses caused by third parties or force majeure.
2. Encryption and passwords
All public web traffic is transmitted over HTTPS with TLS settings supported by our infrastructure.
Account passwords are not stored in plain text — we use bcrypt hashing.
Your duty: use a unique, strong password, do not reuse it on other sites, and do not share it with third parties. Zookzy is not liable for password compromise that results from your own conduct.
When you sign in via OAuth (Google, VK, Yandex, Telegram, Facebook, etc.), security also depends on the identity provider. We do not control their systems and do not warrant their protection.
3. Authentication and session management
We support email/password sign-in and, where available, OAuth providers.
Sessions are protected by server-side mechanisms and cryptographic signing where the stack provides for it.
Administrative and moderation interfaces are strictly role-separated.
Recommendation: enable email notifications for important account changes where the product offers them. This is not a service obligation — it is an extra safeguard for you.
4. Application-layer controls
All state-changing forms (submissions, deletions, payments, etc.) are intended to be protected with CSRF tokens.
We configure HTTP security headers such as X-Content-Type-Options, X-Frame-Options, CSP, Referrer-Policy, and HSTS (where TLS supports it).
After repeated failed logins from one IP address we may require a captcha or apply a temporary lockout.
Liability limitation: these measures reduce but do not remove attack risk. Zookzy does not warrant that an attacker cannot circumvent them.
5. Infrastructure and operations
Production components may run in containerised environments with patching, network segmentation, backups, and event logging. Architecture evolves; we do not commit to uninterrupted availability or invulnerability. A least-privilege approach to data is applied, but human error remains possible.
6. Content safety (listings, media, text)
Listings, photos, and copy may be checked by automated classifiers and by human moderators.
Warning: automation makes mistakes. Legitimate content may be temporarily blocked, and harmful content may sometimes go undetected. Zookzy is not liable for harm arising from content that passed moderation, nor for removal of good-faith content in error.
If you find a violation, report it via the interface (Report). We will review, but we are not obliged to grant every request.
7. Rate limits and automation
We apply request rate limits and heuristics to detect scraping, brute force, spam, and API abuse. Circumventing or attempting to circumvent these measures is a direct breach of the Terms of Service and may result in account suspension without notice.
8. Responsible vulnerability disclosure
If you discover a vulnerability in Zookzy, report it via Contacts with the subject "Security", including technical details sufficient to reproduce the issue without harming users or systems.
Terms:
- We welcome good-faith coordinated disclosure.
- A public bug bounty (paid rewards) is not guaranteed.
- We will not initiate legal action against researchers who act lawfully in good faith, do not read others' data, do not cause damage, and allow a reasonable period — at least 30 calendar days — for remediation before public disclosure.
Zookzy is not liable for consequences of security testing conducted without our prior written consent. Any testing that breaches the Terms of Service is treated as unauthorised interference.
9. Your responsibilities (mandatory user rules)
To minimise risk you must follow the rules below. Breach of any of them disclaims Zookzy liability for related incidents to the extent permitted by law:
- Use a unique, strong Zookzy password that you do not reuse elsewhere. A password manager is recommended.
- Never hand over credentials (login, password, SMS/email codes) to anyone, including people claiming to be Zookzy staff — we never ask for your password.
- Enable two-factor authentication or login alerts where available in your region or product.
- Do not enter OTPs, banking passwords, recovery codes, card numbers, or CVV in Zookzy chats with other users. Doing so is entirely at your own risk.
- Sign out when using shared or public devices.
- Revoke OAuth access at the provider if a device is lost or compromised.
- Report suspicious listings, fraud, or harassment via Report. If you do not report, we cannot act.
- Keep your browser, operating system, and security software up to date.
- Do not use rooted or jailbroken devices to access Zookzy — we do not warrant session security in those cases.
- Do not bypass restrictions, scan Zookzy infrastructure without permission, or use automated scripts to harvest data.
10. Limitation of liability (key risk-allocation clause)
Zookzy AI Technologies (Pvt) Ltd is not liable for:
- Any direct or indirect loss from unauthorised access to your account where access was enabled by your fault (weak password, credential sharing, malware on your device).
- Damage from phishing attacks, including where criminals mimic Zookzy branding.
- Conduct of other users, including fraud, booking defaults, or distribution of harmful content.
- Outages or data incidents at OAuth providers (Google, VK, etc.).
- Temporary unavailability, moderation delays, or mistaken blocking of legitimate content when we acted in good faith to protect the ecosystem.
- Consequences of automated translation, AI recommendations, or voice features if you failed to verify the information.
You acknowledge that use of Zookzy is at your own risk. The Service is provided "as is" without security warranties except where mandatory law prohibits such exclusion. To the fullest extent permitted by applicable law, Zookzy disclaims indirect, incidental, punitive, or consequential damages.
11. Final provisions
This page is an integral part of the Terms of Service. If this text conflicts with the Terms, the Terms prevail. Security matters not covered here are governed by the Privacy Policy and applicable law.
By using Zookzy you confirm that you have read, understood, and accept the rules and limitations above.