---
title: Security policy
---

## Report a vulnerability privately

Do not disclose a suspected vulnerability, credential, exploit, customer
payload, private topology, or other sensitive evidence in a public GitHub issue
or discussion.

Email [oss@cratis.io](mailto:oss@cratis.io?subject=Security%3A) with `Security:`
at the start of the subject. Include only the information needed to route and
reproduce the report:

- affected Cratis repository, package, image, and exact version or commit;
- the behavior you observed and the behavior you expected;
- bounded reproduction steps or a minimal reproducer;
- the conditions required to reach the behavior;
- the potential impact as you understand it; and
- a safe way to contact you for follow-up.

Do not place credentials, customer data, personal data, production data, or
sensitive logs in the first message. Ask for an appropriate private transfer
method when additional evidence is necessary.

## Public issues

Use the affected repository's public issue tracker for ordinary defects and
feature requests that contain no sensitive security information. A public
issue, pull request, build, release, or package does not establish that a
product is secure, compliant, supported, or suitable for a particular
environment.

## Scope and commitments

This policy provides a private reporting route. It does not create a
response-time commitment, service-level agreement, warranty, support plan,
disclosure deadline, bounty, or statement about the security posture of any
Cratis product. Applicable licenses and separately accepted agreements retain
their own terms.
