Coordinated Vulnerability Disclosure Policy
How to report a security vulnerability in Prividium®, what to expect from Matter Labs after you report, and the protections we offer good-faith security researchers.
On this page
1.Purpose
Matter Labs is committed to the security of the Prividium product and welcomes reports of security vulnerabilities from security researchers, customers, users, and the public. This policy describes how to report a vulnerability, what to expect from Matter Labs after you report, and the protections we offer to good-faith security researchers.
This policy is consistent with coordinated vulnerability disclosure practices aligned with ISO/IEC 29147 and ISO/IEC 30111 and satisfies the coordinated vulnerability disclosure policy requirement under the EU Cyber Resilience Act (Regulation (EU) 2024/2847), Annex I, Part II, point (5).
2.Scope
This policy covers security vulnerabilities in the following:
- The Prividium Chain Privacy Engine (CPE) product, including all client-installable components, container images, SDKs, configuration manifests, and documentation.
- Prividium hosted services operated by Matter Labs.
- Supporting infrastructure operated by Matter Labs that directly affects the security of the Prividium product.
For vulnerabilities in ZKsync protocol-level or on-chain components eligible for the existing bug bounty program, reporters should submit through the Immunefi program. Prividium-specific assets are not covered by the Immunefi bug bounty program. Responsible disclosures and customer-reported vulnerabilities for Prividium are accepted exclusively through this policy.
3.How to report
Report vulnerabilities to:
- Email: security@matterlabs.dev
- Subject line:
[CVD]followed by a brief description
Each report should include:
- Description of the vulnerability and the affected component.
- Steps to reproduce, including a proof of concept where possible.
- Potential impact assessment.
- Your contact information for follow-up (Matter Labs will not share this without your permission).
- Whether you would like to be credited in any public disclosure of the fixed vulnerability.
Do not include sensitive secrets (passwords, private keys, seed phrases) in your report. If you need to share sensitive data, Matter Labs will arrange a secure channel.
4.What to expect
Upon receipt of a vulnerability report submitted in accordance with this policy, Matter Labs will respond according to the following timeline:
| Step | Timeline |
|---|---|
| Acknowledgment of receipt | Within 3 business days |
| Initial assessment and triage | Within 10 business days |
| Status update (if remediation is in progress) | At least every 30 days until resolved |
| Notification when a fix is available | Before or concurrent with public disclosure |
| Public disclosure of fixed vulnerability | After the fix is available and users have had reasonable opportunity to apply it |
Timelines may vary based on severity, complexity, and coordination with affected parties. Matter Labs will keep reporters informed of progress throughout the remediation process.
5.Coordinated disclosure
Matter Labs follows coordinated disclosure practices:
- Reporters should allow Matter Labs a reasonable period to investigate, develop a fix, and prepare a security update before any public disclosure. The default disclosure window is 90 days from confirmed receipt. This window may be shortened for actively exploited vulnerabilities or extended for complex issues requiring coordination with third parties.
- Matter Labs will coordinate with the reporter on the timing and content of any public disclosure.
- Once a fix is available, Matter Labs will publicly disclose information about the vulnerability, including a description, affected versions, impact, and corrective measures, as required under the Cyber Resilience Act. In duly justified cases where the security risks of immediate publication outweigh the benefits, Matter Labs may delay public disclosure until users have had a reasonable opportunity to apply the patch; disclosure will still occur.
- Where appropriate and with the reporter’s permission, Matter Labs will credit the reporter in the public disclosure.
6.Safe harbor
Matter Labs will not pursue legal action against individuals who:
- Report vulnerabilities in good faith and in compliance with this policy;
- Make a good-faith effort to avoid privacy violations, data destruction, and disruption to services;
- Do not exploit a vulnerability beyond what is necessary to demonstrate it;
- Do not access, modify, or delete data belonging to other users; and
- Provide Matter Labs reasonable time to address the vulnerability before any public disclosure.
This safe harbor applies to security research activities conducted in accordance with this policy. It does not extend to activities that:
- Violate applicable law;
- Cause harm to users;
- Involve social engineering, phishing, or pretexting;
- Involve unauthorized physical access to Matter Labs facilities or infrastructure; or
- Constitute denial-of-service attacks or other intentional degradation of service availability.
7.Exclusions
The following categories of reports are generally not in scope for this policy:
- Vulnerabilities in third-party services, platforms, or software not operated by Matter Labs.
- Reports of missing security headers or other low-risk configuration findings without a demonstrated security impact.
- Social engineering or phishing attacks directed at Matter Labs personnel.
- Physical security issues at any facility.
- Denial-of-service testing or attacks against Matter Labs systems or infrastructure.
Matter Labs reserves the right to determine, at its sole discretion, whether a particular report falls within the scope of this policy. Reports that fall outside scope may still be reviewed on a discretionary basis but are not subject to the response timelines or safe harbor protections set out in Section 4 and Section 6.
8.Internal handling
Reported vulnerabilities are handled under Matter Labs’ Vulnerability Management Policy, which governs triage, remediation, verification, and closure. Each report is assessed for severity, assigned to the appropriate engineering team, and tracked through resolution.
Vulnerabilities determined to be actively exploited are escalated through the Incident Management Policy. Active exploitation may trigger mandatory reporting obligations to ENISA and the relevant CSIRT in accordance with the EU Cyber Resilience Act (Regulation (EU) 2024/2847).
9.Contact information
For all vulnerability reports and security inquiries related to the Prividium product, use the following contact information:
- Email: security@matterlabs.dev
- security.txt: Available at
/.well-known/security.txton each Prividium deployment
The security.txt file conforms to RFC 9116 and contains the current contact details, encryption key references, and policy URI for coordinated vulnerability disclosure.
Found something? Email security@matterlabs.dev with [CVD] in the subject line.