Security is what Zennoxa Shield is for — we take reports about Shield itself just as seriously.
Please report vulnerabilities privately — do not open a public issue.
Use GitHub's private vulnerability reporting: Report a vulnerability →
This opens a private advisory visible only to you and the maintainers.
Please include:
- A clear description of the issue and its impact
- Steps to reproduce (and the CLI version from
shield version, if relevant) - Any proof-of-concept, logs, or affected endpoints
- Acknowledgement within 3 business days
- A triage assessment and, where valid, a remediation timeline
- Credit in the advisory once a fix ships, if you'd like it
Please give us reasonable time to remediate before any public disclosure. We will not pursue or support legal action against good-faith research that respects this policy and avoids privacy violations, data destruction, or service disruption.
- This repository — the Shield CLI and documentation.
- The hosted service at zennoxa.com — use the same private reporting channel above.
The latest CLI release is supported. The hosted service is continuously updated.
Thank you for helping keep Shield and its users safe.