Report it. We will answer.
Zeno holds credentials to other people's general ledgers. That obliges us to be reachable, specific, and quick when someone finds a problem. This page is the standing invitation and the commitments that come with it.
How to report a vulnerability.
Email [email protected]. You do not need an account, a prior relationship, or a formal write-up. A short description and a way to reproduce it is enough to start.
If a report involves data belonging to a specific firm or client, say so and stop there. Do not access, download, or retain it to prove the point.
- 01Acknowledgement within two business days
A human replies confirming we received it and who is looking at it.
- 02An assessment within ten business days
Whether we could reproduce it, how we rate the severity, and what we intend to do.
- 03Notification when it is fixed
We tell you what shipped. If we decide not to act, we tell you that instead, and why.
- 04Credit if you want it
We are glad to name you when a report leads to a change. We will not name you without asking.
What we ask, and what we promise.
Please do
- Test against your own account and your own connected company
- Give us reasonable time to fix an issue before publishing
- Report promptly once you understand the impact
- Stop at proof of access; do not read or exfiltrate real data
Please do not
- Access, modify, or delete another firm's or client's books
- Run denial-of-service, spam, or automated load testing against production
- Use social engineering or physical intrusion against our staff or vendors
- Post a working exploit publicly before a fix is available
If you follow the above, we will treat your research as authorised, will not pursue legal action over it, and will work with you rather than around you. We do not currently run a paid bounty programme.
The controls behind the promise.
Security posture is not a certification we can wave at you today. It is a set of specific decisions, and these are ours.
Every firm's data lives in its own database schema. Cross-firm access is not a permission we grant carefully. It is a boundary enforced by the storage layer.
QuickBooks tokens are held under envelope encryption and refreshed in a rotation-safe way. They are never exposed to a connected AI client.
The Zeno MCP server sits behind OAuth 2.1 with dynamic client registration, over HTTPS only. You authorise a client; you can withdraw that authorisation.
The control that matters most is not cryptographic. A person approves the exact batch, and every run keeps a reversal path.
Zeno does not train AI models on connected client data, and does not sell or share it for advertising.