SECURITY
ZestSSH is built and maintained by one person — a full-time college student working on this in evenings and weekends. I take security seriously and welcome researchers who help me make the product safer.
Email [email protected] with:
I'll respond within 5 business days to confirm receipt, and follow up within 14 days with a timeline or resolution plan.
I will not pursue legal action against researchers who:
I'd rather hear about a problem than read about it on Twitter. If you're not sure whether something counts, ask.
I'm not a funded company. I'm a college student building this alone. I can't offer cash bounties, but I genuinely appreciate the help and will offer:
For particularly impactful findings, I'll work out something that reflects the value — just ask.
My preferred disclosure window is:
If you need faster disclosure for safety reasons (active exploitation, etc.), tell me and we'll coordinate.
Thanks to the researchers who've helped improve ZestSSH's security:
This list will grow as reports come in. Be the first!