Skip to content

Security: Autter-dev/autter.dev

Security

SECURITY.md

Security

autter.dev is a security product. We take vulnerabilities in our own infrastructure seriously and try to handle reports quickly and without friction.

Reporting a vulnerability

Email security@autter.dev with the details.

Include as much as you can: what you found, how you found it, and whether you have a proof of concept. You do not need a polished writeup. A clear description of the issue is enough to get started.

We will acknowledge your report within 48 hours and follow up with a timeline once we have assessed the severity.

What we ask

  • Give us a reasonable amount of time to fix the issue before disclosing it publicly. For most things, 90 days is reasonable. If you think a shorter window is warranted, say so in your report and we will talk.
  • Do not access, modify, or delete data that does not belong to you while investigating.
  • Do not run automated scanners against production infrastructure without coordinating with us first.

What we commit to

  • We will not pursue legal action against researchers who act in good faith.
  • We will keep you updated as we work through the fix.
  • We will credit you in the changelog entry when we ship the fix, unless you prefer to stay anonymous.

Scope

In scope: anything running at autter.dev, the GitHub App, the analysis pipeline, the API.

Out of scope: social engineering, physical attacks, denial of service, issues in dependencies that are already publicly disclosed.


We do not have a bug bounty program yet. If that changes, this file will say so.

There aren't any published security advisories