If you discover a security vulnerability, please report it privately:
Email: mndinesh674@gmail.com (or create a private GitHub security advisory)
Do NOT:
- Open a public issue
- Disclose publicly before we've addressed it
We will:
- Acknowledge within 48 hours
- Provide an estimated fix timeline
- Credit you in the release notes (if desired)
| Version | Supported |
|---|---|
| 1.x.x | Yes |
| < 1.0 | No |
When self-hosting zynqCloud:
- Use strong
JWT_SECRET(32+ random characters) - Enable HTTPS in production
- Change default database passwords
- Keep dependencies updated
- Use firewall rules to restrict access
- Run regular backups (DB + files +
FILE_ENCRYPTION_MASTER_KEY)