Report to
PGP-encrypted preferred (fingerprint below). Plain-text accepted.
First reply
≤ 3 business days
Triage verdict within 7. Fix timeline by severity (below).
Standards
RFC 9116 · RFC 9700
security.txt at .well-known/security.txt. Disclosure policy on this page.

What to report

We care most about issues that put customer data, billing, or workspace isolation at risk. If you're unsure whether something is in scope, report it anyway — we'll triage.

In scope

  • Authentication bypass on /app or any other dashboard route
  • Cross-workspace data access — reading another tenant's workflows, runs, or credentials
  • Remote code execution or SSRF inside workflow step execution (step.py-class)
  • Stripe billing tampering — invoice amount, tier downgrade, or webhook replay
  • Token theft from the integrations table (Jira / ServiceNow stored creds)
  • Privilege escalation in workspace RBAC (admin/editor/viewer role boundaries)

Out of scope

  • Rate limiting or brute-force protection on public endpoints
  • SPF / DKIM / DMARC failures on outbound Postmark mail
  • Volumetric denial-of-service (run an amplifier test against a staging mirror if you must)
  • Vulnerabilities on third-party-hosted domains we link to
  • Self-XSS that requires the victim to paste payload into their own session

How to report

Email security@cipherrun.io with the following fields. Attach screenshots or proof-of-concept scripts in plain text (no proprietary DOC/PDF attachments).

Encrypt your report (PGP)

Reports may include customer workspace IDs, leaked tokens, or proof-of-concept payloads. Encrypt anything sensitive with our PGP key, then send the ciphertext plus a one-line plaintext subject ("Security report — short tag") to our contact address.

Public key fingerprint
0xCRPLACEHOLDER0000000000000000000000SECRET01

Placeholder fingerprint — we'll swap this for a real key before we hit "publish." Send a gpg --receive-keys request against a known keyserver once this is updated. Until then, please still report — we'll accept plain-text reports and treat them as confidential.

Good-faith safe harbor

When you conduct security research and submit a report under this policy, we consider the activity to be authorized under our acceptable-use policy. We will not pursue civil or criminal action against you for research that:

This commitment applies to CipherRun and our parent organization. It does not waive the rights of any third party. If your research inadvertently impacts a customer, tell us immediately so we can notify them.

Response timeline

We're a small team. We commit to:

StageWindowWhat you get
Acknowledgement≤ 3 business daysConfirmation we received your report and a tracking handle.
Triage verdict≤ 7 calendar daysIn scope / out of scope, severity assignment, named owner.
Critical fix (RCE, cross-tenant access, billing tamper)≤ 7 daysHotfix shipped to production and CVE-style advisory issued.
High fix (auth bypass, privileged action without guard)≤ 30 daysFix shipped and changelog credited to reporter (if desired).
Medium / Low fix≤ 90 daysFix shipped in next release cycle.

Hall of fame

We credit researchers who report valid, in-scope vulnerabilities with their name or handle (or "anonymous" if they prefer). The list below updates as reports ship to production.

No reports yet — the first submission will appear here.