← Back to Security
Vulnerability Disclosure
Report Security Issues
What Can Be Tested
- Authentication and session management vulnerabilities
- Authorization bypass and capability escalation
- Cross-tenant access attempts
- Injection attacks (SQL, command, etc.)
- XSS, CSRF, and logic flaws
- Access control bypasses
- Cryptographic weaknesses
What NOT to Test
- Denial of Service or performance testing
- Accessing other users' accounts
- Physical security or social engineering
- Testing third-party systems (GitHub, AWS, etc.)
- Automated scanning without permission
Report Requirements
Include:
- Vulnerability title and description
- Severity estimate (Critical/High/Medium/Low)
- Affected component and versions
- Step-by-step reproduction instructions
- Proof of concept (code, script, screenshot)
- Impact analysis
- Your contact information
Our Commitment
- Acknowledge receipt within 24 hours
- Triage and classify within 48 hours
- Fix timeline based on severity
- Public credit upon disclosure
- Safe harbor for good-faith researchers
Full Policy
See docs/legal/VULNERABILITY_DISCLOSURE_POLICY.md for complete disclosure policy, scope, and coordinated disclosure details.