SECURITY & TRUST

Security Policy

Our commitment to transparency, vulnerability coordination, and researcher recognition.

Security Hall of Fame

Researcher Acknowledgments

We extend our sincere gratitude to the independent security researchers who have responsibly disclosed vulnerabilities to help keep zn and the AI ecosystem secure.

SEC-2026-01High Severity
September 2026

Control-plane authorization gap on policy and consensus handlers

Discovered that control-plane endpoints (/api/v1/policies* and /api/v1/consensus*) validated tenant API authentication but omitted function-level authorization checks, allowing non-admin tenant keys to alter policies or consensus state. Remediation enforced strict SuperAdmin role checks and consensus witness verification.

Reporting a Vulnerability

If you believe you have discovered a security vulnerability in zn, the MCP Gateway, or any usezn.com infrastructure, please report it directly to our security team. We take all responsible disclosures seriously and investigate them promptly.

Security Contact: security@usezn.com
PGP Key: Available upon request
Response SLA: Initial acknowledgment within 24 hours; triage within 48 hours

Please include detailed steps to reproduce the issue, proof-of-concept scripts or requests, and any relevant environment details. Testing against local Docker containers or isolated test accounts is strongly encouraged.

Safe Harbor Commitment

We consider security research conducted in accordance with this policy to be authorized. If you make a good-faith effort to comply with responsible disclosure (avoiding user data access, service disruption, and privacy violations), we will:

  • Not initiate or pursue legal action against you
  • Work with you transparently to validate and remediate the issue
  • Coordinate the public advisory and attribution according to your preferences

Scope

In Scope

  • Core zn gateway daemon and consensus protocol
  • Cloud API endpoints (api.usezn.com)
  • Client SDKs (zn-gate NPM/PyPI)
  • Authentication and access control mechanisms
  • Model jailbreak bypasses against /v30/analyze

Out of Scope

  • Denial of Service (DoS/DDoS) attacks
  • Social engineering or phishing targeting zn personnel
  • Third-party services hosting our assets (e.g., AWS, Cloudflare)
  • Automated scanner spam without actionable proof-of-concept

Recognition & Rewards

We value the effort required to identify security flaws. For qualifying vulnerabilities, we offer:

  • Public Attribution: Permanent listing in our Security Hall of Fame and release notes.
  • Platform Subscriptions: Free access to our Growth tier plans for personal or research use.
  • Direct Advisory Collaboration: Full coordination on disclosure timing, advisory drafts, and CVE assignment.
← Back to DocumentationSystem Status →