Skip to content

Security: RJ-Flash/zara-sentinel

Security

SECURITY.md

Security & Ethical Use Policy

Supported Versions

Currently, the main branch of Zara Sentinel is actively supported for security updates.

Reporting a Vulnerability

If you discover a vulnerability within Zara Sentinel itself, please report it privately via the ArchonAI internal security tracker or by emailing the maintainers. Do not open public issues for zero-day vulnerabilities in the tool.

🚨 Ethical Use Policy (White-Box Testing ONLY)

Zara Sentinel is an autonomous AI penetration tester built exclusively for White-Box Security Auditing.

By using, contributing to, or executing Zara Sentinel, you agree to the following constraints:

  1. Authorization: You may only aim Zara Sentinel at codebases, applications, or APIs for which you have explicit, written authorization to perform security testing.
  2. Access Limitation: Zara Sentinel is designed to analyze environments where it has source code, architectural documentation, or direct developer-level access.
  3. No Malicious Usage: You must not attempt to fork, modify, or retrain Zara Sentinel's core logic to perform unauthenticated, adversarial (Black-box) attacks against public internet infrastructure.
  4. Compliance: Usage of this tool must comply with all local, federal, and international cyber laws.

ArchonAI disclaims any liability for the misuse of Zara Sentinel for unauthorized offensive operations.

There aren't any published security advisories