Z.ai open-sourced ZCode under Apache-2.0 and had CAICT and NSFOCUS certify its exfiltration bucket is empty
r/LocalLLaMA (445 upvotes), corroborated by GitHub API for zai-org/ZCode·high signal
Three days after the community found ZCode uploading local repository snapshots, Z.ai open-sourced the whole harness (desktop app, web workspace, backend, Agent CLI, runtime) at github.com/zai-org/ZCode. The GitHub API shows the repo created 2026-09-20 and already at 4,932 stars. Z.ai says v3.14.0 removes the Repo Wiki feature and the snapshot upload path entirely, that the zcode-prod Alibaba Cloud OSS bucket and every object in it were deleted, and that CAICT and NSFOCUS independently verified the zero-data state; it also commits to a paid vulnerability reporting process. The top comment (239 upvotes) notes this is the second time an AI vendor has answered a data-exfiltration finding by open-sourcing the client.