| Version | Supported |
|---|---|
| 0.1.x | ✅ |
DO NOT open a public GitHub issue for security vulnerabilities.
- Email (preferred): security@zks.wasif.app
- GitHub Private Advisory: Create a private security advisory
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Any suggested fixes (optional)
- Initial Response: Within 48 hours
- Status Update: Within 7 days
- Fix Timeline: Depends on severity
- Critical: 24-72 hours
- High: 7 days
- Medium: 30 days
- Low: 90 days
We follow responsible disclosure:
- We will acknowledge your report within 48 hours
- We will work with you to understand and validate the issue
- We will develop and test a fix
- We will coordinate public disclosure timing with you
- We will credit you in security advisories (unless you prefer anonymity)
ZKS Protocol implements multiple layers of security:
- Post-Quantum Cryptography: ML-KEM-1024 for key exchange (NIST Level 5)
- 256-bit Post-Quantum Computational Security: Wasif-Vernam cipher
- Memory Safety: Written in Rust
- Anti-Replay Protection: Bitmap-based nonce tracking
- Formal Verification: Critical components verified with ProVerif
We do not currently have a formal bug bounty program, but we deeply appreciate security researchers who responsibly disclose vulnerabilities and will acknowledge your contribution publicly.