Skip to content

Security: Infisical/infisical

SECURITY.md

Security Policy

Reporting a vulnerability

Please do not open a public GitHub issue for a security problem.

Report it through our vulnerability disclosure policy at https://infisical.com/vulnerability-disclosure.

Please include what you found, where, how to reproduce it, what an attacker could achieve, and how you would like to be credited.

Scope and safe harbour

The full scope of the program, along with our safe harbour and coordinated disclosure terms, is set out in the policy linked above.

Rewards

This is a vulnerability disclosure program, not a bug bounty. It offers acknowledgement and public credit rather than payment.

Infisical's paid bug bounty is a separate private, invitation-only program covering Infisical Cloud. It is not open to public submissions, and reports made through this repository are not eligible for its rewards. Strong reports here are a good route to an invitation.

Supported versions

Security fixes ship in the latest release. We always recommend running the latest version of Infisical. If you self-host, upgrading promptly is the fastest way to stay protected.

General security contact

For compliance documentation, security questionnaires, penetration-test reports and SOC 2 requests, use security@infisical.com. That address is not a vulnerability intake channel.

There aren't any published security advisories