If you discover a security vulnerability in EnvSimple CLI, please report it responsibly.
Do not open a public issue for security concerns.
- Email: Send details to contact@envsimple.com
- GitHub: Open a private security advisory in the repository
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if available)
We aim to acknowledge security reports within 48 hours and provide a fix timeline within 5 business days.
We follow coordinated disclosure:
- You report the issue privately
- We confirm and develop a fix
- We release a patched version
- We publicly disclose the vulnerability with credit to the reporter
When using EnvSimple CLI:
- Keep your CLI updated to the latest version
- Use strong authentication
- Never commit
.envor.envsimple.localfiles - Review audit logs regularly
- Rotate credentials periodically
- Use environment-specific access controls
Security Team: contact@envsimple.com