Security Policy
Our commitment to transparency, vulnerability coordination, and researcher recognition.
Security Hall of Fame
Researcher AcknowledgmentsWe extend our sincere gratitude to the independent security researchers who have responsibly disclosed vulnerabilities to help keep zn and the AI ecosystem secure.
Control-plane authorization gap on policy and consensus handlers
Discovered that control-plane endpoints (/api/v1/policies* and /api/v1/consensus*) validated tenant API authentication but omitted function-level authorization checks, allowing non-admin tenant keys to alter policies or consensus state. Remediation enforced strict SuperAdmin role checks and consensus witness verification.
Reporting a Vulnerability
If you believe you have discovered a security vulnerability in zn, the MCP Gateway, or any usezn.com infrastructure, please report it directly to our security team. We take all responsible disclosures seriously and investigate them promptly.
Please include detailed steps to reproduce the issue, proof-of-concept scripts or requests, and any relevant environment details. Testing against local Docker containers or isolated test accounts is strongly encouraged.
Safe Harbor Commitment
We consider security research conducted in accordance with this policy to be authorized. If you make a good-faith effort to comply with responsible disclosure (avoiding user data access, service disruption, and privacy violations), we will:
- Not initiate or pursue legal action against you
- Work with you transparently to validate and remediate the issue
- Coordinate the public advisory and attribution according to your preferences
Scope
In Scope
- Core zn gateway daemon and consensus protocol
- Cloud API endpoints (
api.usezn.com) - Client SDKs (
zn-gateNPM/PyPI) - Authentication and access control mechanisms
- Model jailbreak bypasses against
/v30/analyze
Out of Scope
- Denial of Service (DoS/DDoS) attacks
- Social engineering or phishing targeting zn personnel
- Third-party services hosting our assets (e.g., AWS, Cloudflare)
- Automated scanner spam without actionable proof-of-concept
Recognition & Rewards
We value the effort required to identify security flaws. For qualifying vulnerabilities, we offer:
- Public Attribution: Permanent listing in our Security Hall of Fame and release notes.
- Platform Subscriptions: Free access to our Growth tier plans for personal or research use.
- Direct Advisory Collaboration: Full coordination on disclosure timing, advisory drafts, and CVE assignment.