Report a vulnerability
Email security@sentrail.dev. PGP encryption is available — request our public key at the same address. We acknowledge reports within 24 hours and target an initial triage within 3 business days.
Scope
- The Sentrail application and APIs
- The agent runtime and provider router
- Authentication and authorization flows
Out of scope
- Findings from automated scanners without a working proof of concept
- Denial-of-service via volumetric traffic
- Social engineering of ZerwOne staff
- Issues in third-party services we do not operate
Safe harbor
ZerwOne Network LLC will not pursue legal action against researchers who, in good faith, comply with this policy: avoid privacy violations, data destruction, and service degradation; only interact with accounts you own or have explicit permission to test; and give us a reasonable opportunity to remediate before public disclosure.