If you discover a security vulnerability in ZLAR, please report it responsibly.
Email: security@zlar.ai
Do not open a public issue for security vulnerabilities. We will acknowledge receipt within 48 hours and provide a timeline for a fix.
| Version | Supported |
|---|---|
| 1.0.x | Yes |
ZLAR is built on five security principles:
- Fail closed. If the gate is down, all actions are denied.
- No intelligence in the gate. The gate classifies and enforces. It does not decide what is safe.
- Policy is a human artifact. Ed25519-signed. Agents cannot modify the rules that govern them.
- Every feature is an attack surface. Only add convenience when the pain of not having it is proven.
- Patience over speed. When in doubt, deny.