Ziora / Security model

Security model

Ziora reads source code that is often confidential, so it is built to touch as little as possible and to be easy to audit. This page describes what it does with your code, every connection it makes and where it keeps data.

Last updated 1 October 2026 · Applies to Ziora 0.1.0

How Ziora is built

Ziora has two parts, and both run on your computer: the desktop app, built with Flutter, and an analysis engine written in Python. Release builds include the engine as a standalone program, so you don't need Python installed.

Ziora's architecture The Ziora app talks to the Ziora engine with JSON-RPC over standard input and output. The engine reads your repository without running it, writes review state to a .ziora folder, and runs Semgrep, gitleaks and OSV-Scanner as separate processes with fixed arguments, no shell and timeouts. Everything runs on your computer. Your computer Ziora app Flutter desktop interface Ziora engine Bundled in release builds JSON-RPC stdin / stdout Semgrep SAST · metrics off gitleaks Secrets · --redact OSV-Scanner Dependencies Separate processes, no shell, fixed arguments, timeouts Your repository Read only, never executed reads and parses .ziora/ folder Notes and triage, git-ignored writes review state
  • The app starts the engine as a child process and talks to it with JSON-RPC over standard input and output. No network port is opened, so nothing else on your machine or network can talk to the engine.
  • If the engine stops while you work, the app restarts it and reopens your project on the next action.

Your code

  • Never executed. The engine reads files and parses syntax trees. It never imports, builds, installs or runs anything from the repository it reviews.
  • Read in place. File access from the app is confined to the project folder. Requests for paths outside it, including path traversal, are rejected, and there are tests for it.
  • Hostile files are expected. XML such as Android manifests is parsed with entity declarations refused, so a malicious file can't expand entities or reach outside the project.
  • Secret values stay out. When Ziora finds a hardcoded secret, it records where it is, not what it is. gitleaks always runs with --redact, so secret values never reach Ziora or its files.
  • Notes stay out of git. Review state lives in a .ziora/ folder inside the project, which gets its own .gitignore so notes aren't committed by accident.

Network access

Ziora has no server. It has no telemetry, analytics, crash reporting or update checks. These are the only times it connects to the internet:

WhenConnects toWhat is sent
You clone a repository or pull from the branch menuYour git host, using the git installed on your computerWhatever git sends. Ziora uses the sign-in git already has (Git Credential Manager, SSH keys) and never asks for, sees or stores a password or token.
OSV-Scanner checks your dependenciesapi.osv.devPackage names, versions and ecosystems from your lockfiles. No source code.
Semgrep loads its default rule setsemgrep.devA request for the rules. Ziora runs Semgrep with --metrics=off and --disable-version-check.
You install a scanner from inside Zioragithub.com for gitleaks and OSV-Scanner, pypi.org for SemgrepA standard download request.

Everything else works offline, including all of Ziora's own analysis. If Semgrep can't reach its registry, Ziora runs it with a built-in rule set instead and tells you.

Scanners

Semgrep, gitleaks and OSV-Scanner are optional. Ziora's own checks work without them.

  • Each scanner runs as a separate process with a fixed argument list, never through a shell, and with a timeout.
  • When Ziora installs gitleaks or OSV-Scanner, it downloads the official release for your system from GitHub and verifies its SHA-256 against the checksums file published with that release. If the checksum doesn't match, the download is discarded.
  • Installed scanners live in Ziora's own tools folder. Installing them needs no administrator rights and adds nothing to your PATH.
  • Semgrep is a Python package. If you choose to install it, Ziora uses pip.

AI agents

Ziora doesn't send anything to an AI provider. You decide whether to give your agent the fix plan or connect it to Ziora.

  • Fix plans never include secret values.
  • The MCP server speaks the Model Context Protocol over standard input and output. It never exposes secret values and writes nothing but protocol messages to its output.
  • Once your agent reads a fix plan or queries Ziora, what it does with that information is governed by the agent and its provider.

Data on your computer

This is everything Ziora itself stores. Ziora has no server, so there is no copy anywhere else. Scanners you install may keep their own caches.

WhatWhere
Review state: findings, triage, notes and coverage.ziora/ inside each project
Recent projectsWindows: %APPDATA%\Ziora\recent.json
macOS and Linux: ~/.config/Ziora/recent.json
Engine logWindows: %LOCALAPPDATA%\Ziora\logs
macOS: ~/Library/Logs/Ziora
Linux: ~/.local/state/ziora
Scanners installed by ZioraWindows: %LOCALAPPDATA%\Ziora\tools
macOS: ~/Library/Application Support/Ziora/tools
Linux: ~/.local/share/ziora/tools

Deleting a project's .ziora/ folder removes its review. Deleting the folders above removes everything else.

Verify a download

Each installer on the download list shows its SHA-256 checksum. Before you run an installer, compare that value with the checksum of the file you downloaded.

Windows (PowerShell)

Get-FileHash .\Ziora-Setup-0.1.0.exe -Algorithm SHA256

macOS

shasum -a 256 ~/Downloads/<file name>

Linux

sha256sum ~/Downloads/<file name>

If the values don't match, don't run the file. Delete it and download it again from this site.

Report a vulnerability

If you find a security problem in Ziora or on this website, email security@ziorasecurity.com.

  • Include the Ziora version, your operating system, what you found and the steps to reproduce it.
  • Please don't include real secrets or someone else's data in your report.
  • Give us a reasonable amount of time to fix the issue before you share it publicly.

We'll confirm that we received your report and keep you updated while we work on a fix. Our contact details are also published in security.txt.