Reporting a vulnerability

If you believe you've found a security problem, please tell us privately at [email protected]. Include what you found, how to reproduce it and what an attacker could do with it. Please don't access other customers' data, run denial-of-service tests or use automated scanners against production.

We'll confirm we received your report, keep you updated while we fix it, and credit you once it's resolved if you'd like.

In scope

  • Seeing or changing another workspace's data
  • Authentication, session, two-factor and API key weaknesses
  • Making our servers connect to private or internal addresses (SSRF)
  • Taking over a custom domain or status page you don't own
  • Cross-site scripting, injection and secrets leaking into responses

See also the security overview.