Security & Bug Bounty
Report security vulnerabilities privately. Never report one in a public GitHub issue, pull request, or Slack thread.
Reporting a Vulnerability
Use either channel:
- Email security@archestra.ai.
- Open a private report from the repository's Security tab. Only you and the maintainers can see it.
Include:
- The affected Archestra version and deployment type (Docker or Helm).
- The steps to reproduce, or a proof of concept.
- The impact: what an attacker can read, change, or run.
Bug Bounty
Archestra does not run a formal bug bounty program. The team may compensate you for a responsibly disclosed vulnerability based on its severity.