Security Policy

Supported Versions

Security fixes are prioritized for the latest tagged release.

VersionSupported
v0.1.xYes

Reporting a Vulnerability

Please do not open a public GitHub issue for suspected vulnerabilities.

Report privately by emailing:

security@zt-infra.org

If GitHub private vulnerability reporting is enabled for the repository, you may also use the private advisory flow instead of email.

Include:

We aim to acknowledge reports within 2 business days and provide a remediation plan or status update within 7 business days.

Scope

Primary scope:

In scope:

Out of scope:

For the full design-level threat model, see THREAT_MODEL.md.

Safe Harbor

Good-faith security research that avoids privacy violations, data destruction, and service disruption is welcome.