Security & Bug Bounty

Report security vulnerabilities privately. Never report one in a public GitHub issue, pull request, or Slack thread.

Reporting a Vulnerability

Use either channel:

Include:

  • The affected Archestra version and deployment type (Docker or Helm).
  • The steps to reproduce, or a proof of concept.
  • The impact: what an attacker can read, change, or run.

Bug Bounty

Archestra does not run a formal bug bounty program. The team may compensate you for a responsibly disclosed vulnerability based on its severity.