Security · VNX-DNA 9.0.0

Security

Containers are sealed with AES-256-GCM; --key-file is checked on full decode; --max-container-bytes bounds what a forged superblock may claim; --expect-archive-id / --expect-sha256 bind a decode to a known archive. Parsers and native kernels are fuzzed (libFuzzer, hypothesis) and built with ASan/UBSan in CI. VNX-Secure adds a policy-controlled control plane: see VNX-Secure. Report vulnerabilities via Security.

Last updated 2026-10-08