Zayo · Vulnerability Disclosure

Zayo Vulnerability Disclosure

Vulnerability disclosure

Zayo Group publishes a full, named Vulnerability Disclosure Policy on its own domain, with scope, expectations, commitments and an explicit safe-harbour clause. Reports are taken through a third-party platform (Inspectiv), not by email. There is no /.well-known/security.txt on any Zayo host, so the policy is discoverable only by browsing the site.

Zayo publishes a vulnerability disclosure policy for reporting security issues.

CompanyTelecommunicationsNetworkingConnectivityFiberInfrastructureBandwidthCloud ConnectivityOrderingTicketing
Program:

Disclosure Policy

Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy

Security Contact

Source

Vulnerability Disclosure

Raw ↑
specification: API Commons VulnerabilityDisclosure
specificationVersion: '0.1'
provider: Zayo Group Holdings
providerId: zayo-group
generated: '2026-09-06'
method: searched
probe: true
source: https://www.zayo.com/security/
http_status: 200
description: >-
  Zayo Group publishes a full, named Vulnerability Disclosure Policy on its own domain, with
  scope, expectations, commitments and an explicit safe-harbour clause. Reports are taken
  through a third-party platform (Inspectiv), not by email. There is no /.well-known/security.txt
  on any Zayo host, so the policy is discoverable only by browsing the site.
policy:
  published: true
  title: Zayo Group Vulnerability Disclosure Policy
  url: https://www.zayo.com/security/
  submission_url: https://client.inspectiv.com/vdp/zayo-group/submit-report
  platform: Inspectiv
  bug_bounty: false
  bug_bounty_note: >-
    Nothing on the page offers a monetary reward. It is a disclosure programme, not a bounty.
  scope: Any digital assets owned, operated, or maintained by Zayo Group.
  out_of_scope: >-
    Vulnerabilities in systems not owned by Zayo should be reported to the appropriate vendor
    or applicable authority.
  safe_harbor: true
  safe_harbor_terms:
  - Authorized with respect to applicable anti-hacking laws; Zayo will not initiate or support legal action for accidental, good-faith violations.
  - Authorized with respect to anti-circumvention laws; no claim for circumvention of technology controls.
  - Exempt from Terms of Service / Acceptable Use Policy restrictions that would interfere with security research, waived on a limited basis.
  - Considered lawful and conducted in good faith; if a third party initiates legal action, Zayo will make it known the research complied with the policy.
  - Applies only to legal claims under the control of Zayo; it does not bind independent third parties.
  disclosure_window_days: 180
  disclosure_window_note: >-
    Zayo asks for "a reasonable amount of time (at least 180 days from the initial report) to
    resolve the issue before you disclose it publicly".
  provider_commitments:
  - Respond to your report promptly, and work with you to understand and validate it.
  - Keep you informed about the progress of a vulnerability as it is processed.
  - Work to remediate discovered vulnerabilities in a timely manner, within operational constraints.
  - Extend safe harbor for vulnerability research related to this policy.
  researcher_expectations:
  - Follow this policy and any other relevant agreements; this policy prevails on conflict.
  - Report any vulnerability discovered promptly.
  - Avoid violating others' privacy, disrupting systems, destroying data, or harming user experience.
  - Use only the Official Channels to discuss vulnerability information with Zayo.
  - Test only in-scope systems.
  - Limit data access to the minimum needed for a proof of concept; stop and report immediately on encountering PII, PHI, card data or proprietary information.
  - Interact only with test accounts you own or have explicit permission to use.
  - Do not engage in extortion.
security_txt:
  served: false
  evidence: >-
    /.well-known/security.txt returns 404 on zayo.com, www.zayo.com, developer.zayo.com and
    trust.zayo.com, and 403 (AWS API Gateway "Missing Authentication Token") on api.zayo.com and
    auth.api.zayo.com. Probed 2026-09-06; see well-known/zayo-group-well-known.yml.
  gap: >-
    A machine cannot find this policy. Zayo has done the hard part — a real policy with safe
    harbour — and skipped the one line of discoverability that would let a scanner or an agent
    locate it. Publishing /.well-known/security.txt with Policy: https://www.zayo.com/security/
    and Contact: https://client.inspectiv.com/vdp/zayo-group/submit-report would close it.
evidence:
- url: https://www.zayo.com/security/
  status: 200
  kind: disclosure policy
  fetched: '2026-09-06'
  keywords:
  - Vulnerability Disclosure Policy
  - Safe Harbor
  - Systems in Scope
  - Official Channels
  - 180 days
- url: https://client.inspectiv.com/vdp/zayo-group/submit-report
  status: 200
  kind: submission portal
  note: Linked from the policy page as the Official Channel; hosted by Inspectiv, not Zayo.
- url: https://www.zayo.com/.well-known/security.txt
  status: 404
  kind: absent
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/zayo-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.