Security

Security & Responsible Disclosure

How to report a vulnerability, what's in scope, and the safe harbor we extend to good-faith research.

Reporting a vulnerability

Please do not open a public issue for a security vulnerability. Report it privately so we can fix it before disclosure.

Preferred: open a private advisory via GitHub Private Vulnerability Reporting. Alternatively, email us with a description, steps to reproduce, and the potential impact.

We acknowledge reports within 48 hours. When an issue is resolved we credit reporters in our release notes, unless you prefer to stay anonymous.

Safe harbor

We consider security research conducted in good faith under this policy to be authorized, and we will not pursue or support legal action against you for accidental, good-faith violations, including under anti-hacking or anti-circumvention laws.

If a third party brings action against you for activity that complied with this policy, we will make our authorization known. This safe harbor covers claims under our control and cannot bind third parties.

Scope and rules of engagement

In scope: our web surfaces, the API gateway, and the open-source services in our repository. You may also test self-hosted deployments that you operate yourself.

Never access, modify, or exfiltrate data belonging to any tenant other than a test account you control. Confirm access-control findings with your own resources. No denial of service, load testing, or disruption of live streams. No pushing media to ingest endpoints you do not own.

Limit any data access to the minimum proof-of-concept needed to demonstrate an issue. If you encounter credentials, personal data, or keys, stop, do not save them, and tell us in your report.

Disclosure

We practice coordinated disclosure: give us a reasonable window to remediate and check with us on timing before publishing. We are happy to credit your work once a fix is out.

The machine-readable version of this policy is published at /.well-known/security.txt.