Skip to content

Security: estuary/connectors

SECURITY.md

Reporting Security Vulnerabilities

Estuary is committed to the security of our platform and the safety of our customers. We appreciate the efforts of security researchers who help us maintain a secure product.

This document describes how to report a security vulnerability to Estuary and what you can generally expect from us. It is informational guidance for reporters. It is not a formal security policy, an audited control, or a contractual commitment, and it does not create any obligations on Estuary's part.

Reporting a Vulnerability

Please do not report security vulnerabilities through public GitHub issues.

Preferred method: Use GitHub's built-in "Report a vulnerability" feature in the Security tab of the repository where the vulnerability exists. This keeps the report private and associated with the relevant codebase.

Alternatively, you can email security@estuary.dev. This is equally acceptable, especially for vulnerabilities that span multiple repositories or affect Estuary's infrastructure.

What to Include

  • A description of the vulnerability and its potential impact
  • Steps to reproduce the issue
  • Proof-of-concept code, if available
  • Any plans or intentions for public disclosure

What to Expect

We aim to:

  • Acknowledge your report within a couple of business days
  • Share timeline and status updates after triage, with transparency about remediation progress
  • Keep an open dialog to discuss the issue throughout the process
  • Notify you as the vulnerability analysis progresses through review
  • Credit you after the vulnerability has been validated and fixed, if desired

Bug Bounty

Estuary does not currently operate a bug bounty program, and we do not offer monetary rewards for vulnerability reports. We are grateful for responsible reports and are happy to publicly credit reporters who would like recognition.

Scope

We are interested in reports affecting:

  • The Estuary platform and its components
  • Estuary-maintained open source repositories
  • Estuary's public-facing infrastructure

Good Faith Research

Estuary does not intend to pursue legal action against individuals who report vulnerabilities in good faith through the channels above, provided they:

  • Test systems without harming Estuary or its customers
  • Stay within the scope described in this document
  • Do not access, modify, or delete customer data
  • Adhere to applicable laws
  • Refrain from public disclosure before a mutually agreed-upon timeframe

Out of Scope

The following are generally not of interest:

  • Social engineering attacks against Estuary employees
  • Denial of service attacks
  • Physical security issues
  • Issues in third-party applications or services not maintained by Estuary

Additional Information

For questions about how Estuary handles vulnerability reports, please contact security@estuary.dev.

There aren't any published security advisories