One engine, two packages
The inspection engine is the same on OPNsense and pfSense. Only the integration layer differs, so a fix in classification or policy reaches both platforms in the same release rather than one of them a quarter later.
Engineering
Zedmos is a FreeBSD-native security engine, not a portable application that happens to run on a firewall. That decision costs us portability and buys inspection at line rate on hardware a branch office can afford.
The inspection engine is the same on OPNsense and pfSense. Only the integration layer differs, so a fix in classification or policy reaches both platforms in the same release rather than one of them a quarter later.
Detection work is judged on precision against real traffic. A rule that fires on legitimate sessions is a defect, not a tuning exercise for the customer, and it is treated as one before the release goes out.
A CycloneDX SBOM is published with each version, so an auditor can see exactly which components a given firewall is running without asking us. This is the ground the European Cyber Resilience Act obligations are met on.
Reports go to security@zedmos.com and are acknowledged rather than routed into a support queue. The disclosure policy and the supported-version window are published, not negotiated case by case.