SECURITY

Report a vulnerability.

We build software that decides whether other software is allowed to run. If we get that wrong, we want to hear it from you before we hear it from an incident.

LAST UPDATED — 4 AUGUST 2026

Reporting

Email security@zerowrite.ai. If you would like to encrypt your report, ask for our PGP key in a first message and we will send it before you share details.

Please include, as far as you are able:

What we commit to

StageOur target
Acknowledge your reportWithin 2 business days
Initial assessment and severityWithin 5 business days
Fix or documented mitigation for critical issuesWithin 30 days
Credit in the release notesOn request, at disclosure

We will keep you updated as the fix progresses, tell you when it ships, and agree disclosure timing with you rather than imposing it.

Safe harbour

If you make a good-faith effort to comply with this policy, we will not pursue or support legal action against you for your research. Good faith means: you avoid privacy violations, degradation of service, and destruction of data; you only interact with accounts you own or have explicit permission to test; and you give us reasonable time to fix an issue before disclosing it publicly.

In scope

Out of scope

How the product is designed to fail

These are deliberate properties, useful context when assessing impact:

What we do not claim

No product stops everything. ZeroWrite does not defend against an attacker who already has kernel-level or administrator-level control of the machine, and it is not a substitute for patching, backups, or least privilege. We would rather say so here than imply otherwise.

Related: Privacy Policy · Terms of Service