Estuary is committed to the security of our platform and the safety of our customers. We appreciate the efforts of security researchers who help us maintain a secure product.
This document describes how to report a security vulnerability to Estuary and what you can generally expect from us. It is informational guidance for reporters. It is not a formal security policy, an audited control, or a contractual commitment, and it does not create any obligations on Estuary's part.
Please do not report security vulnerabilities through public GitHub issues.
Preferred method: Use GitHub's built-in "Report a vulnerability" feature in the Security tab of the repository where the vulnerability exists. This keeps the report private and associated with the relevant codebase.
Alternatively, you can email security@estuary.dev. This is equally acceptable, especially for vulnerabilities that span multiple repositories or affect Estuary's infrastructure.
- A description of the vulnerability and its potential impact
- Steps to reproduce the issue
- Proof-of-concept code, if available
- Any plans or intentions for public disclosure
We aim to:
- Acknowledge your report within a couple of business days
- Share timeline and status updates after triage, with transparency about remediation progress
- Keep an open dialog to discuss the issue throughout the process
- Notify you as the vulnerability analysis progresses through review
- Credit you after the vulnerability has been validated and fixed, if desired
Estuary does not currently operate a bug bounty program, and we do not offer monetary rewards for vulnerability reports. We are grateful for responsible reports and are happy to publicly credit reporters who would like recognition.
We are interested in reports affecting:
- The Estuary platform and its components
- Estuary-maintained open source repositories
- Estuary's public-facing infrastructure
Estuary does not intend to pursue legal action against individuals who report vulnerabilities in good faith through the channels above, provided they:
- Test systems without harming Estuary or its customers
- Stay within the scope described in this document
- Do not access, modify, or delete customer data
- Adhere to applicable laws
- Refrain from public disclosure before a mutually agreed-upon timeframe
The following are generally not of interest:
- Social engineering attacks against Estuary employees
- Denial of service attacks
- Physical security issues
- Issues in third-party applications or services not maintained by Estuary
For questions about how Estuary handles vulnerability reports, please contact security@estuary.dev.