01How to report
Email [email protected]. PGP encryption is available — request our public key at the same address. Our machine-readable contact is published at /.well-known/security.txt.
A useful report includes:
- The affected host, endpoint, or component, and the vulnerability class.
- Reproduction steps or a proof of concept a reviewer can follow.
- The impact you believe it has, and any prerequisites (authenticated? which role? which plan?).
- Timestamps and source IPs of your testing, so we can separate it from real attacks.
- Whether you intend to publish, and on what timeline.
Please do not include third-party data in your report. If you accessed data that is not yours, stop, tell us in the report, and delete your copy.
02What we commit to
| Stage | Our target |
|---|---|
| Acknowledgement of your report | Within 24 hours |
| Initial triage and severity assessment | Within 3 business days |
| Status update while work continues | At least every 7 days |
| Fix for a critical or high issue | Target 30 days from triage |
| Fix for a medium or low issue | Target 90 days from triage |
| Coordinated public disclosure | By mutual agreement after the fix ships |
03In scope
- The Sentrail web application and its authenticated surfaces.
- The Sentrail API, server functions, and the MCP server, including token handling.
- Authentication, session, and authorization flows, including tenant isolation and row-level security bypasses.
- The agent runtime and approval gates — in particular anything that would let an action reach a production system without approval.
- Provider integrations (GitHub, Supabase, Vercel) and the storage and handling of their tokens.
- The static-analysis scanner and pentest runner services, including container isolation.
- Webhook endpoints and their signature verification.
- Billing flows where a flaw grants entitlements without payment.
04Out of scope
- Automated scanner output without a demonstrated, working proof of concept.
- Denial of service through volumetric traffic, load testing, or resource exhaustion.
- Social engineering, phishing, or physical attacks against ZerwOne personnel or facilities.
- Missing hardening headers or best-practice recommendations with no demonstrated impact.
- Vulnerabilities requiring a rooted or malware-compromised device, or a heavily outdated browser.
- Issues in third-party services we do not operate — report those to the vendor.
- Email configuration findings (SPF, DKIM, DMARC) with no demonstrated spoofing impact.
- Self-XSS, clickjacking on pages with no sensitive action, or content spoofing without a security consequence.
05Rules of engagement
- Test only against accounts and data you own. Create your own workspace rather than touching another tenant.
- Stop as soon as you confirm a vulnerability. Do not pivot, escalate persistence, or enumerate further than needed to prove impact.
- Do not access, modify, exfiltrate, or destroy data belonging to anyone else, and do not degrade the Service for other users.
- Do not use the scanner or pentest runners as a springboard against third-party systems.
- Give us a reasonable opportunity to fix the issue before disclosing it publicly.
- Comply with applicable law throughout.
06Safe harbor
If you make a good-faith effort to comply with this policy during your research, we will consider your activity authorized. ZerwOne Network LLC will not initiate or support legal action against you under computer-misuse law, breach of contract, or the anti-circumvention provisions of the DMCA in connection with that research, and we will make it known that your actions were authorized if a third party brings a claim.
This safe harbor covers only claims that ZerwOne Network LLC controls. It cannot bind our infrastructure providers or other third parties. If you are unsure whether a specific test is in scope, ask us first at [email protected] — we would much rather answer a question than argue about it afterwards.
07Recognition and rewards
We do not currently run a paid bug bounty programme, and we will not imply one exists. With your permission we credit reporters in our release notes and maintain a researchers page. If we launch a bounty, we will announce it here first.
08Findings in customer systems
This policy covers Sentrail itself. If you found a vulnerability in an application that happens to use Sentrail, report it to that application's owner, not to us. If you believe Sentrail is being used to scan a system without authorization, email [email protected] — our Acceptable Use Policy explains how we handle that.
Written to follow ISO/IEC 29147 (vulnerability disclosure) and the safe-harbor language pattern recommended by CISA's Binding Operational Directive 20-01 template and the disclose.io terms, with a machine-readable contact per RFC 9116. Provided for information; it is not legal advice.
