Security

Security Policy & Vulnerability Disclosure

Zoundio AB builds and operates the Gibson App. We take the security of our players' accounts and data seriously, and we welcome reports from security researchers who help us find problems before they are abused. This page explains how to reach us, what you can expect back, and the terms under which we will not pursue legal action against you.

Last updated 18 August 2026 · This policy is our coordinated vulnerability disclosure policy for the purposes of Regulation (EU) 2024/2847 (the Cyber Resilience Act).

Report a vulnerability

Email us directly. Please do not open a public issue, post on social media, or share the details anywhere else until we have had a chance to fix the problem.

security@zoundio.com

To help us triage quickly, please include:

  • The affected product, URL, endpoint or app version
  • Clear, reproducible steps — a short screen recording is ideal
  • What an attacker could actually achieve, and how you assess the impact
  • Any accounts, IPs or user agents you used, so we can match our logs
  • How you would like to be credited, if you want to be

Our machine-readable contact details are published at /.well-known/security.txt.

What you can expect from us

Within 48 hours

We acknowledge your report and confirm we are looking at it. If you have not heard from us in 48 hours, please resend — assume it got lost, not ignored.

Within 5 business days

We tell you whether we could reproduce the issue, how we assess its severity, and our intended remediation plan.

Until it is closed

We keep you updated on progress, let you know when a fix ships, and agree public disclosure timing with you.

Safe harbour

If you make a good-faith effort to follow this policy while researching and reporting a vulnerability to us, then:

  • We will not initiate or support legal action against you in connection with your research, and we will not report you to law enforcement.
  • We consider your research authorised activity under our Terms of Use, and we waive any claim that it breaches them.
  • If a third party brings action against you for research that followed this policy, we will make it known that your activity was authorised.

This commitment covers your research, not unrelated activity. It cannot waive the rights of third parties or obligations we owe under Swedish or EU law. If you are unsure whether something is in bounds, email us at security@zoundio.com and ask first — we would much rather answer the question than argue about it afterwards.

Scope

In scope

  • The Gibson App for iOS (com.berggram.amped) and Android (com.zoundio.amped)
  • The websites gibson.app and www.gibson.app, including the web player and practice tools
  • Our public APIs and backend services used by the app
  • Account, authentication, subscription and payment flows

Out of scope

  • Denial-of-service and volumetric or stress testing of any kind
  • Social engineering, phishing or physical attacks against our staff, users or offices
  • Reports from automated scanners with no demonstrated, working impact
  • Missing hardening headers or best-practice findings with no exploitable impact
  • Vulnerabilities in third-party services we do not operate (report those to their owners)
  • Anything requiring a rooted, jailbroken or otherwise compromised device the attacker already controls

Rules of engagement

  1. Give us a reasonable chance to fix the issue before you tell anyone else. Our default coordination window is 90 days from your first report.
  2. Use only your own accounts and test data. Do not access, modify or download data belonging to other users.
  3. Stop as soon as you have confirmed a vulnerability exists — do not pivot further into our systems.
  4. Do not exfiltrate data. If you encounter personal data by accident, stop, delete it and tell us in your report.
  5. Keep your testing within the scope listed above and do not degrade the service for other users.

Recognition

We are a small team and we do not currently run a paid bug bounty programme, so please do not expect a monetary reward. What we do offer is a fast, human response, a real fix, and public credit on this page if you want it. We are always happy to confirm your findings in writing for your portfolio or CV.

Regulatory contact

Zoundio AB, Götgatan 34, 118 32 Stockholm, Sweden, is the manufacturer of the Gibson App for the purposes of Regulation (EU) 2024/2847 (the Cyber Resilience Act). Enquiries from national authorities, CSIRTs or market surveillance authorities can be sent to security@zoundio.com.

For privacy and personal data questions, see our Privacy Policy. For general support, contact app.support@gibson.com.