OwnNode Agent protects a bearer-authenticated private API and can optionally receive media and reviewed financial transaction data. Please do not disclose a suspected vulnerability in a public issue.
Report security concerns by emailing zenit027@proton.me with:
- the affected release or commit;
- the impact and reproduction steps;
- relevant deployment details with secrets removed; and
- any suggested mitigation.
Never include tokens, passwords, SMS content, account identifiers, private URLs, or user media in a report. There is currently no paid bug bounty program.