We actively maintain and provide security updates for the following versions of ZAP:
| Version | Supported |
|---|---|
| 1.0.x | ✅ |
| < 1.0 | ❌ |
The security of ZAP and user privacy are our highest priorities. If you discover a vulnerability or potential cryptographic weakness, please disclose it responsibly:
- Do NOT open a public GitHub issue.
- Report the vulnerability via a Private GitHub Security Advisory.
- Include detailed steps to reproduce the issue, proof-of-concept payloads, and expected vs actual behavior.
- Zero-Knowledge Principle: The server never has access to raw passwords, plaintext messages, private keys, or unencrypted media.
- Hardware-Accelerated Web Crypto API: We exclusively use the native browser
window.crypto.subtleimplementation. - No Third-Party Analytics: ZAP contains zero third-party trackers, analytics scripts, or telemetry.