CipherRun takes security of customer data and the automation platform seriously. If you've found something we should know about, the page below explains what to send, how to encrypt it, and what we'll do in response.
.well-known/security.txt. Disclosure policy on this page.We care most about issues that put customer data, billing, or workspace isolation at risk. If you're unsure whether something is in scope, report it anyway — we'll triage.
/app or any other dashboard routestep.py-class)integrations table (Jira / ServiceNow stored creds)Email security@cipherrun.io with the following fields. Attach screenshots or proof-of-concept scripts in plain text (no proprietary DOC/PDF attachments).
/app/workflow-builder, /api/v1/workflows/run, integrations table rowcurl one-liner, screenshot, or short script. We need to reproduce on a staging workspace.Reports may include customer workspace IDs, leaked tokens, or proof-of-concept payloads. Encrypt anything sensitive with our PGP key, then send the ciphertext plus a one-line plaintext subject ("Security report — short tag") to our contact address.
Placeholder fingerprint — we'll swap this for a real key before we hit "publish." Send a gpg --receive-keys request against a known keyserver once this is updated. Until then, please still report — we'll accept plain-text reports and treat them as confidential.
When you conduct security research and submit a report under this policy, we consider the activity to be authorized under our acceptable-use policy. We will not pursue civil or criminal action against you for research that:
This commitment applies to CipherRun and our parent organization. It does not waive the rights of any third party. If your research inadvertently impacts a customer, tell us immediately so we can notify them.
We're a small team. We commit to:
| Stage | Window | What you get |
|---|---|---|
| Acknowledgement | ≤ 3 business days | Confirmation we received your report and a tracking handle. |
| Triage verdict | ≤ 7 calendar days | In scope / out of scope, severity assignment, named owner. |
| Critical fix (RCE, cross-tenant access, billing tamper) | ≤ 7 days | Hotfix shipped to production and CVE-style advisory issued. |
| High fix (auth bypass, privileged action without guard) | ≤ 30 days | Fix shipped and changelog credited to reporter (if desired). |
| Medium / Low fix | ≤ 90 days | Fix shipped in next release cycle. |
We credit researchers who report valid, in-scope vulnerabilities with their name or handle (or "anonymous" if they prefer). The list below updates as reports ship to production.