تخطَّ إلى المحتوى

اختبار اختراق هجين

هدف واحد. يُختبَر من البداية إلىالنهاية.

اختبار محدد النطاق لتطبيق ويب أو جوال واحد، يجمع بين مشغلي زيرو داي وأوبسيديان. تستلم ملخصًا مجانيًا أولًا؛ ويُؤكد التقرير الكامل وشروط إعادة الاختبار بصورة منفصلة.

هدف مفوّض ← ملف أدلة

شكل المخرج

شاهد بنية الأدلة. من دون بيانات عملاء.

يوضح هذا المثال كيف تجتمع حدود التفويض والأدلة القابلة لإعادة الإنتاج والمعالجة وحالة إعادة الاختبار.

داخل ملف الأدلةمثال مركب خيالي · بلا بيانات عملاء

الحدود

ROEتفويض قبل أي اختبار نشط

الأدلة

R-01نتيجة قابلة للإعادة ومسار هجوم

الإغلاق

RTحالة المعالجة ونتيجة إعادة الاختبار

فئات نتائج توضيحية

  1. 01ثغرات المصادقة والجلسات
  2. 02تزوير الطلب من الخادم (SSRF)
  3. 03تحكّم وصول معطوب و IDOR
  4. 04أسرار وبيانات دخول مكشوفة
  5. 05الحقن وإساءة منطق العمل

ضوابط الملف

  • حدود ROE
  • خطوات الإعادة
  • بصمة الدليل
  • مسؤول المعالجة
  • حالة إعادة الاختبار
نتيجة واحدة، بالكاملR-01

تحكّم وصول معطوب (IDOR) في استرجاع الفواتير

الخطورةمرتفعة

الفئة OWASP A01 · تحكّم وصول معطوب

مسار الهجوم
وثق مسار الفواتير (GET /api/v2/invoices/{id}) معرّفًا تسلسليًا من الرابط ولم يتحقق من أن الفاتورة تخص الحساب الطالب. أدى إنقاص المعرّف من مستخدم عادي إلى قراءة فواتير حسابات أخرى.
الدليل
أُنشئ حسابان ضمن قواعد الاشتباك. طلب الحساب «أ» المعرّف 41022؛ وباستبداله بمعرّف يملكه الحساب «ب» أعاد فاتورة «ب» — الاسم والعنوان وبنود الفاتورة — باستخدام جلسة «أ». حُفظ الطلب والرد وبُصِما.
الأثر
يستطيع أي مستأجر مُصادق تعداد وقراءة سجلات فوترة كل مستأجر آخر. كشف بيانات شخصية وتجارية عبر المستأجرين دون أي تصعيد صلاحيات.
المعالجة
فرض تحقق ملكية من جهة الخادم (يجب أن يطابق حساب الفاتورة حساب الطالب) قبل إعادة السجل، والانتقال إلى معرّفات غير تسلسلية كدفاع إضافي. تحقق منها مشغّل زيرو داي، لا المحرك.
إعادة الاختبار

أُضيف تحقق الملكية، وأُعيد الاختبار بالحسابين نفسيهما — لم تعد القراءة عبر المستأجرين ممكنة. مغلقة.

مثال مركب خيالي للتوضيح. لا يحتوي على عميل أو هدف أو نتيجة أو اعتماد أو نتيجة ارتباط حقيقية.

المحرّك المملوك تحت العمل

يوسّع أوبسيديان الوصول. ويقرر البشر ما يصبح دليلًا.

يرسم أوبسيديان السطح ويربط الفجوات في مسارات هجوم محتملة. يستغل المشغلون هذه المسارات ويعيدونها ويقررون ما يهم.

  1. 01

    استطلاع واكتشاف ثغرات بمقياس الآلة — أبعد ممّا يُعدّده أي ماسح.

  2. 02

    نتائج تُربط في مسارات هجوم حقيقية، كما يفعل الخصم.

  3. 03

    كل نتيجة تُستغَل وتُعاد يدويًا قبل أن تصل تقريرك.

كيف يجري

من التفويض إلى الإغلاق

  1. 01

    التحديد والتفويض

    تطبيق واحد متفق عليه خطيًا تحت قواعد اشتباك موقعة قبل بدء الاختبار.

  2. 02

    المحرّك + الاستغلال اليدوي

    يرسم أوبسيديان المسارات المحتملة؛ ويستغلها المشغلون من البداية إلى النهاية.

  3. 03

    سرد مسار الهجوم

    شاهد نقطة الدخول والمدى والخطورة والإصلاحات. يأتي الملخص أولًا.

  4. 04

    المعالجة وإعادة الاختبار

    يُتفق على النطاق والتوقيت أثناء التأكيد ويُسجلان في خطة المعالجة.

الارتباط بلا غموض

$1,500الدفع عند التسليم

يشمله التقرير الكامل

  • تطبيق ويب أو جوال واحد
  • نتائج لمسارات هجوم متحقق منها بشريًا
  • ملخص تنفيذي مجاني
  • تقرير كامل بالإعادة والخطورة والمعالجة
يُؤكد فتح تقرير اختبار الاختراق الكامل بصورة منفصلة بسعر 1,500 دولار أمريكي وبشروط صافي 7 أيام. يشمل الارتباط ملخصاً مجانياً؛ ويُتفق على أي إعادة اختبار للمعالجة أثناء تأكيد النطاق.اطلب ارتباطك

اطلب الارتباط

أخبرنا بالهدف. وسنتولّى الباقي.

اذكر التطبيق والقيود؛ ونرد عليك بالنطاق والخطوات التالية.

لا يبدأ أي اختبار قبل اعتماد النطاق وقواعد الاشتباك.

اختياري

قواعد الاشتباك · v1.0اقرأها كاملة قبل الموافقة
OBSIDIAN PENETRATION TEST — RULES OF ENGAGEMENT Version 1.0 — July 2026 These Rules of Engagement (this "ROE") are between Zeroday Technology LLC, a Delaware limited liability company with contact address legal@zeroday.group ("ZD"), and the business identified in the submission below ("Customer"). This ROE is effective on the date of Customer's electronic acceptance of these terms (the "Effective Date"). This ROE, and not ZD's free initial security-scan authorization or any other ZD terms, is the sole and entire agreement governing the Obsidian engagement, and in any conflict with any other ZD terms or any marketing or website copy this ROE controls. READ THIS ROE IN FULL BEFORE CHECKING THE BOX. BY A SINGLE CHECKBOX YOU AGREE TO TERMS THAT DIFFER FROM ZD'S FREE SCAN: (A) YOU AUTHORIZE ZD TO ACTIVELY EXPLOIT THE APPLICATION YOU NAME (SECTION 1); (B) YOU MAY OWE A CONDITIONAL FLAT FEE OF USD 1,500 — DUE ONLY IF, AFTER RECEIVING THE FREE SUMMARY, YOU AFFIRMATIVELY REQUEST THE FULL REPORT (SECTION 5); (C) ZD'S TOTAL LIABILITY IS CAPPED AND ALL WARRANTIES ARE DISCLAIMED (SECTION 9); AND (D) DISPUTES ARE RESOLVED BY THE DIFC COURTS' SMALL CLAIMS TRIBUNAL OR BY DIAC ARBITRATION, NOT IN COURT GENERALLY (SECTION 11). NO FEE IS DUE AT ACCEPTANCE, AT SUBMISSION OF THIS REQUEST FORM, OR FOR THE FREE SUMMARY. 1. AUTHORIZATION FOR ACTIVE EXPLOITATION. Customer authorizes ZD to perform a full penetration test of the single web or mobile application identified by Customer in the request form, together with the backend APIs, endpoints, and application accounts that directly serve that application, but excluding any shared or multi-tenant infrastructure, control plane, or service owned or operated by a hosting, cloud, or CDN provider even where it serves the application (the "Target"). THIS AUTHORIZATION EXPRESSLY INCLUDES ACTIVE EXPLOITATION: Customer expressly consents to ZD (a) identifying and actively exploiting vulnerabilities in the Target, including chaining and escalating multiple vulnerabilities, to prove and demonstrate real-world impact; (b) using, replaying, creating, and escalating credentials, tokens, sessions, and keys issued by Customer or discovered within the Target's own scope, solely to reach resources within that scope; (c) developing and executing proof-of-concept code that evidences a finding; and (d) accessing the smallest number of other in-scope user, account, or tenant records reasonably necessary to evidence a broken-access-control, authorization, or isolation finding, minimizing, masking, and not retaining such data beyond the redacted evidence set. Because Customer owns or controls the Target and, under Section 6(b), holds authority over all accounts and data within it, Customer's authorization extends to ZD's access to any account, session, credential, or data within the Target to evidence a finding, and such access is authorized access to the Target's system regardless of the nominal account holder. ZD will use the least intrusive method that establishes a finding and will access only the minimum data reasonably necessary to evidence it. All authorized activity is confined to the Target; ZD will not test, pivot into, or exploit any system, domain, tenant, account, or data outside the Target. Customer grants this authorization on its own behalf and, as authorized agent, on behalf of any affiliate or group entity that owns or operates the Target, and represents it is authorized to bind each such entity to this ROE. To the extent Customer holds the right to grant it (as warranted in Section 6 and evidenced by the validation in Section 2), Customer's authorization constitutes express authorization, and negates any claim of access "without authorization" or in excess of authorized access, for purposes of the US Computer Fraud and Abuse Act (18 U.S.C. §1030), the UAE Cybercrime Law (Federal Decree-Law 34/2021), and any analogous computer-access statute. For clarity, this is the opposite of ZD's free initial scan, which does not exploit. 2. AUTHORITY VALIDATION; TESTING WINDOW; CONTACTS; EMERGENCY STOP. ZD's authorization to begin testing does not arise, and the Testing Window does not start, until Customer completes ownership/authority validation for the Target: for a web Target, by publishing a ZD-issued token via a DNS TXT record or a file at a ZD-specified path on the Target's own domain; for a mobile Target, by evidencing control of the publishing developer account or by another method ZD accepts. ZD may decline or suspend testing where validation is not completed, and stores the validation artifact with the acceptance record. Active testing (enumeration and exploitation) is authorized for fourteen (14) calendar days beginning on the later of the Effective Date and completion of that validation (the "Testing Window"), unless the parties agree a different window by email to legal@zeroday.group. Access authorization under Section 1 applies only during the Testing Window and terminates automatically at its close, subject to revival for the Retest under Section 4. Customer's submitting contact, or a technical contact Customer identifies by email to legal@zeroday.group before testing begins, will be monitored and reachable during the Testing Window. On acceptance ZD will provide Customer an operational contact monitored during the Testing Window for pause, stop, and safety escalations; the emergency-stop and revocation rights may be exercised through that contact or legal@zeroday.group. On becoming aware of (a) unintended service disruption, (b) signs of an active third-party compromise of the Target, or (c) any exposure of data belonging to systems outside the Target, ZD will pause testing, record the time and observed effect, and notify Customer's contact without undue delay, resuming only after Customer confirms it is safe. On request ZD will furnish a copy of this accepted ROE and its acceptance and validation record as evidence of Customer's authorization, which the parties may present to a hosting, cloud, or other provider or to a competent authority. Customer may pause or revoke testing at any time under Section 10. 3. EXCLUDED & PROHIBITED ACTIVITIES. Notwithstanding Section 1, this authorization does NOT extend to, and ZD will not: (a) perform any denial-of-service, distributed denial-of-service, resource-exhaustion, load, stress, or volumetric testing, or any act whose primary or likely effect is to degrade or deny availability of the Target; (b) intentionally destroy, delete, encrypt, ransom, corrupt, or permanently alter Customer data, systems, or configurations, or plant persistent malicious code; (c) exfiltrate, retain, sell, publish, or disclose Customer data for any purpose other than evidencing a finding to Customer under this ROE; (d) test, or take any action that would affect, any asset, account, domain, user, tenant, or infrastructure of any third party, hosting provider, or cloud provider outside the Target — for clarity, other users, accounts, or tenants within the Target are inside scope and minimal proof access to them is authorized under Section 1; or (e) conduct social-engineering, phishing, or physical-intrusion testing. This Section does not restrict ZD's own use of its testing infrastructure and tooling under Section 8. If proving a finding would require a prohibited action, ZD will instead describe the impact theoretically and coordinate with Customer's contact. Nothing ZD is authorized to do is intended to cause damage or loss within the meaning of 18 U.S.C. §1030(a)(5) or the UAE Cybercrime Law. 4. DELIVERABLES; LICENSE; RETEST. ZD will first deliver, free of charge, a written executive summary of findings (the "Summary"), which ZD provides whether or not Customer proceeds. The Summary states, per finding, the affected area, a severity indication, and business impact, but deliberately omits step-by-step reproduction, exploit detail, and remediation guidance. After receiving the Summary, Customer may, at its sole option, request the full report, which adds, for each reported finding, (i) step-by-step reproduction, (ii) a formal severity rating, and (iii) remediation guidance (the "Full Report"). Customer requests the Full Report only by an affirmative written request — made through the request/confirmation control ZD provides, or by written instruction to legal@zeroday.group — that restates the USD 1,500 / NET 7 obligation and is separately confirmed by Customer; that request triggers the Fee under Section 5. ZD will not transmit the Full Report before that request is recorded, and ZD's transmission of the Full Report absent a recorded request does not create any payment obligation; mere receipt, opening, or non-response to the Summary does not request the Full Report or trigger the Fee. ZD records the date, time, and identity of the requesting person. Delivery of a document containing elements (i)–(iii) constitutes delivery of the Full Report, and the sufficiency or usefulness of any finding does not affect the Fee. If requested within thirty (30) calendar days after delivery of the Full Report, ZD will perform, at no additional charge, one (1) re-validation of Customer's remediation of the reported findings against the same Target (the "Retest"); for the sole purpose of the Retest, Customer's authorization under Section 1 (and the CFAA / UAE Cybercrime authorization therein) is revived and extends to a re-validation window of up to five (5) calendar days commencing when ZD begins the Retest, limited to re-testing the specific findings being re-validated, and terminates on completion of the Retest. Each deliverable is a point-in-time assessment and is not a certification of security. ZD retains all intellectual property in its methodologies, tooling, and deliverables, and grants Customer a non-exclusive, non-transferable, royalty-free license to use the Summary and, upon payment of the Fee, the Full Report solely for Customer's internal remediation and evaluation. Customer's access to or use of the Full Report before the Fee is paid is licensed only on condition of payment when due; failure to pay when due terminates that license retroactively, any continued use is unauthorized use of ZD's intellectual property, and ZD may by written notice require Customer to cease use of and permanently delete the Full Report, without waiving ZD's right to the Fee as a debt due. Customer shall not publish either deliverable or share it with a competitor of ZD without ZD's prior written consent. 5. FEE; CONDITIONAL PAYMENT. THE SUMMARY IS GENUINELY FREE, AND NO FEE OR OTHER AMOUNT IS DUE AT ACCEPTANCE OF THIS ROE, AT SUBMISSION OF THE REQUEST, OR FOR THE SUMMARY. A ONE-TIME FLAT FEE OF UNITED STATES DOLLARS ONE THOUSAND FIVE HUNDRED (USD 1,500) PER ENGAGEMENT (the "Fee") BECOMES DUE ONLY UPON CUSTOMER'S AFFIRMATIVE REQUEST FOR THE FULL REPORT UNDER SECTION 4. Upon that request Customer becomes unconditionally obligated to pay the Fee, and that obligation is not extinguished or reduced by Customer's later non-use, rejection, or criticism of the Full Report. IF CUSTOMER DOES NOT REQUEST THE FULL REPORT, CUSTOMER OWES ZD NOTHING AND MAY KEEP AND USE THE SUMMARY AT NO CHARGE. ZD will deliver the Full Report promptly after the request; the Fee is payable within seven (7) calendar days after delivery ("NET 7"). The Full Report is "delivered," and NET 7 begins, when ZD sends it (or a secure link to it) to the contact email in the request form, regardless of whether Customer opens, downloads, or accesses it; ZD will keep any secure link live for at least fourteen (14) days, and Customer is responsible for ensuring that address receives ZD email. Issuance of an invoice is not a condition to the Fee becoming due; ZD may issue an invoice as a convenience, but NET 7 runs from delivery regardless of invoicing. The Fee is fixed regardless of the number or severity of findings and covers the one free Retest under Section 4. The Fee is exclusive of any value-added or similar indirect tax lawfully due on the engagement (other than taxes on ZD's net income), for which Customer is responsible. To dispute the Fee, Customer must deliver to legal@zeroday.group, within the NET 7 period, a written notice stating the specific, good-faith basis for the dispute; absent such timely notice the Fee is conclusively deemed undisputed and due; a dispute as to part of an amount does not suspend Customer's obligation to pay any portion not so disputed; and a dispute raised in bad faith or without a stated basis does not defer the Fee. Any amount not paid when due may accrue interest at the maximum rate permitted by applicable DIFC/UAE law, and ZD may on written notice suspend the Retest and the Full Report license until all amounts are paid in full; this suspension remedy never reaches the already-delivered free Summary. 6. CUSTOMER WARRANTIES; INDEMNITY. Customer represents and warrants, as a continuing condition of this authorization, that (a) the individual accepting this ROE has authority to bind Customer; that individual identifies the Customer entity, personally represents that Customer is a business entering this ROE for business or commercial purposes (and not a consumer), and personally warrants authority to bind Customer, and if that individual lacked such authority they personally make the representations in this Section and are personally bound by this ROE, including the Fee obligation in Section 5; (b) Customer owns the Target or otherwise holds the full legal right and authority to authorize an active penetration test of it, including authority over all accounts, data, and application-layer resources of the Target and over any hosting, cloud, or third-party components in the Target's path, and where the Target processes data belonging to Customer's own customers, tenants, or other controllers, Customer holds all rights and consents necessary to authorize ZD's access to that data for testing or has excluded such data from scope, and the Target and its data are not subject to any third-party contractual restriction prohibiting the testing authorized here; (c) Customer has identified to ZD (in the request form or by email to legal@zeroday.group before testing begins) each hosting, cloud, CDN, or WAF provider in the Target's path and either holds current written provider approval for this testing or the provider's published policy permits customer-initiated testing of the Target without prior approval (identifying which), will provide ZD on request a copy of or reference to any such approval, and will complete any provider source-IP allow-listing before testing begins; and (d) neither Customer, nor any direct or indirect owner holding fifty percent (50%) or more, is subject to sanctions administered by OFAC, the EU, the UK, or the United Nations, or ordinarily resident in a comprehensively sanctioned jurisdiction. Customer will defend, indemnify, and hold harmless ZD and its personnel from and against any third-party claim, and all resulting losses, damages, fines, and reasonable legal fees and costs, arising out of or relating to (i) any breach of this Section 6, including any inaccuracy in the representation of ownership of or authority over the Target; (ii) any claim by a hosting, cloud, or other third party arising from testing Customer authorized; or (iii) Customer's failure to obtain any required provider consent. ZD will promptly notify Customer of the claim, give Customer sole control of defense and settlement (no settlement admitting ZD liability or imposing non-monetary obligations on ZD without its consent), and reasonably cooperate at Customer's expense. A breach of this Section voids ZD's authorization — ab initio as to provider-owned components, and otherwise prospectively — and entitles ZD to stop work. 7. CONFIDENTIALITY. Each party shall keep the other's confidential information — including the Target details, the Summary, the Full Report, all findings, any data accessed during testing, and ZD's methodologies — confidential for two (2) years from the Effective Date, using at least reasonable care. Confidential information does not include information that is or becomes public without breach, was rightfully known without a duty of confidence, or is independently developed without use of the disclosing party's information. A party may disclose to the extent required by law or legal process, giving reasonable prior notice where lawful, and may use and disclose this ROE and the acceptance record as necessary to enforce or defend its rights. 8. DATA PROTECTION. ZD will collect only the evidence reasonably necessary to demonstrate and reproduce each finding, store all testing artifacts and accessed data in encrypted form, transmit deliverables only by encrypted email or secure link, and not retain live credentials after the Testing Window (except as needed for a timely-requested Retest). For any personal data appearing in findings or accessed during exploitation, Customer is the data controller and ZD acts as a limited-purpose processor acting only on Customer's documented authorization in this ROE. ZD may engage subcontractors and use third-party or cloud-hosted testing tools (including out-of-band interaction and scanning services), provided ZD remains responsible for their acts and omissions, binds each to confidentiality and data-protection obligations no less protective than this ROE, and does not thereby route Customer personal data outside the safeguards of this Section; Customer authorizes such sub-processing, and on written request ZD will identify material subcontractors and tools. If ZD becomes aware of any unauthorized access to, or accidental or unlawful loss, disclosure, or alteration of, Customer data held by ZD under this ROE, ZD will notify Customer's designated contact without undue delay and in any event within seventy-two (72) hours, describe the nature and scope of the incident and the data affected, and reasonably cooperate with Customer's breach-response and notification obligations. ZD will securely delete live captured data, credentials, and proof-of-concept artifacts within thirty (30) days after delivery of the Full Report or, where a Retest is requested, within thirty (30) days after completion of the Retest, whichever is later (or, if no Full Report is requested, within thirty (30) days after delivery of the Summary), except that ZD may retain a redacted evidence set, together with this ROE and the acceptance and validation record, for up to twelve (12) months for audit and legal-defense purposes. 9. NO WARRANTIES; LIMITATION OF LIABILITY. THE TESTING AND ALL DELIVERABLES ARE PROVIDED AS-IS, WITH NO WARRANTIES EXPRESS OR IMPLIED. TO THE MAXIMUM EXTENT PERMITTED BY LAW, ZD'S AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THIS ROE IS LIMITED TO THE GREATER OF (A) THE FEES ACTUALLY PAID BY CUSTOMER UNDER SECTION 5 AND (B) UNITED STATES DOLLARS FIVE THOUSAND (USD 5,000). Neither party is liable for indirect, consequential, incidental, special, or punitive damages. These limits do not apply to liability for gross negligence, willful misconduct, or fraud. 10. TERM & REVOCATION. This ROE terminates on the later of (a) the close of the Testing Window under Section 2 or (b) delivery of the Summary, except that Sections 3 through 9, 11, 12, and 13 survive termination. Notwithstanding termination, Customer's right to request the Full Report, and the resulting Fee obligation, survive and remain exercisable for thirty (30) calendar days after delivery of the Summary, and a request made in that period is governed by this ROE as if it were in force; after that window ZD may decline to provide the Full Report. Customer may revoke this authorization at any time by email to legal@zeroday.group; upon receipt, ZD will cease active testing within twenty-four (24) hours, after which ZD's authorization to access the Target ends. Revocation and expiry of the Testing Window operate prospectively only: all access to and testing of the Target performed by ZD before revocation took effect, or before the Testing Window closed, was and remains authorized by Customer, and Customer irrevocably waives any claim that such prior access was without authorization or in excess of authorized access under 18 U.S.C. §1030, Federal Decree-Law 34/2021, or any analogous statute. Revocation does not waive a Fee already due for a Full Report that ZD has delivered. 11. GOVERNING LAW; DISPUTES. This ROE is governed by the laws applicable in the Dubai International Financial Centre (DIFC). Disputes with an amount in controversy at or below AED 500,000 shall be finally resolved by the DIFC Courts' Small Claims Tribunal. Other disputes shall be finally resolved by arbitration administered by the Dubai International Arbitration Centre (DIAC) under the DIAC Arbitration Rules 2022, seat DIFC, sole arbitrator, English. 12. ELECTRONIC ACCEPTANCE. The full text of this ROE is displayed to Customer before the acceptance control, and the acceptance record binds the SHA-256 hash of this ROE text as displayed. By checking the acceptance box and submitting the request form, the signer (a) confirms authority to bind Customer and personally warrants that authority (and, if lacking it, is personally bound under Section 6); (b) confirms Customer's ownership of or authority over the Target; (c) confirms Customer is a business acting for business or commercial purposes and not a consumer, and the parties agree the consumer-disclosure requirements of 15 U.S.C. §7001(c) do not apply; (d) acknowledges having been shown the full text of this ROE before checking the box; and (e) agrees to this ROE in full, INCLUDING THE AUTHORIZATION OF ACTIVE EXPLOITATION IN SECTION 1, THE CONDITIONAL USD 1,500 PAYMENT OBLIGATION IN SECTION 5, THE LIMITATION OF LIABILITY IN SECTION 9, AND THE DIFC / DIAC DISPUTE RESOLUTION IN SECTION 11. This constitutes an electronic signature and a binding agreement under the US E-SIGN Act (15 U.S.C. §§7001 et seq.), UAE Federal Decree-Law 46/2021, and the DIFC Electronic Transactions Law (DIFC Law No. 2 of 2017). ZD records the ROE version, a SHA-256 hash of the exact accepted text, the date, time, and identifying details of acceptance, and the authority-validation artifact as evidence of this agreement. Before checking the box Customer is able to download, print, and save a copy of this ROE, and ZD will furnish the exact accepted version (identified by its version and SHA-256 hash) to Customer on request to legal@zeroday.group. The Fee obligation additionally rests on Customer's separate affirmative request for the Full Report under Section 4, at which point ZD restates the USD 1,500 / NET 7 terms for a fresh confirmation. 13. GENERAL. (a) Entire agreement; no reliance. This ROE is the entire agreement on its subject matter and supersedes all prior or contemporaneous communications, proposals, and representations, including any statement on ZD's website, free-scan pages, or marketing copy; Customer has not relied on any statement outside this ROE. (b) Severability. If any provision is held invalid, it will be reformed to the minimum extent needed to be enforceable or, failing that, severed, and the remainder stays in force; the authorization in Section 1 and the exclusions in Section 3 are each independently severable and survive invalidity of any other provision, including any tax or late-payment provision in Section 5. (c) Amendment. This ROE may be amended only in a writing (including email) agreed by both parties. (d) Assignment. Neither party may assign or transfer this ROE or any rights or licenses under it, by operation of law or otherwise, without the other party's prior written consent, except that either party may assign to a successor in a merger or sale of substantially all its assets on written notice; any purported assignment in breach is void. (e) Force majeure. Neither party is liable for delay or failure to perform (other than a payment obligation) caused by events beyond its reasonable control, including outages, acts of government, or denial of access to the Target by a provider; the affected party will notify the other and use reasonable efforts to resume, and the Testing Window is extended by the period of the event. (f) Notices. Notices are in writing by email — to ZD at legal@zeroday.group and to Customer at the email address in the request form (or the technical contact for operational notices under Section 2) — and are deemed received on transmission during a business day at the recipient's location, otherwise the next business day, absent a bounce; either party may change its address by notice. (g) Limitation of action. No claim arising out of this ROE (other than a payment claim or a matter within the Section 9 carve-outs) may be brought more than twelve (12) months after the party knew or should have known of the facts giving rise to it. (h) No waiver. No failure or delay in exercising a right waives it. (i) No third-party beneficiaries. This ROE creates no rights in any third party, and the DIFC Contracts (Rights of Third Parties) Law does not apply. (j) Relationship. The parties are independent contractors.