Security Disclosure v1.0

Service: zkOrigoPlus Blockchain Compliance API

Provider: ADCX LAB HUB (202503273076, JM1033406-H, Malaysia)

Effective Date: 2025-11-29

Version: 1.0

Security Contact: admin@autodigitalcoin.com
Response Time: 24-72 hours for critical vulnerabilities

1. Security Architecture

1.1 Stateless Design

1.2 Infrastructure

2. Encryption

2.1 In Transit

2.2 At Rest

3. Authentication and Authorization

3.1 API Key Authentication

3.2 IAM Policies

4. Rate Limiting and DDoS Protection

4.1 Rate Limits

Tier Limits
Sandbox 10/min, 100/hour, 500/day per IP
Starter 2,500/month per API key
Professional 10,000/month per API key
Enterprise 50,000/month per API key

4.2 DDoS Protection

5. Vulnerability Management

5.1 Responsible Disclosure

If you discover a security vulnerability:

  1. Email: admin@autodigitalcoin.com
  2. Subject: "Security Vulnerability - zkOrigoPlus"
  3. Include: Description, steps to reproduce, impact assessment
  4. Do NOT publicly disclose until we confirm a fix

5.2 Response Timeline

5.3 Bug Bounty

No formal bug bounty program. Acknowledgment provided for responsible disclosures.

6. Incident Response

6.1 Detection

6.2 Response Process

  1. Incident detection and triage
  2. Containment (disable affected endpoints if needed)
  3. Investigation and root cause analysis
  4. Remediation and patching
  5. Post-incident review (for major incidents)

6.3 Notification

7. Compliance and Certifications

7.1 Current Status

zkOrigoPlus does NOT currently hold:

7.2 AWS Compliance

Infrastructure inherits AWS certifications:

8. Third-Party Dependencies

8.1 External RPC Providers

Service queries public blockchain RPCs. Security NOT under our control:

8.2 Payment Processor

9. Data Security

9.1 What We Store

9.2 What We Do NOT Store

See Privacy Policy for details.

10. Security Best Practices for Users

11. Known Limitations

12. Security Roadmap

Planned improvements (no timeline guaranteed):

13. Contact

Security Issues: admin@autodigitalcoin.com

General Support: support@zkorigoapi.com