Responsible disclosure
Reporting a vulnerability
If you believe you've found a security issue in AuthPlane — the authorization server, any SDK, or this website — please report it via one of the paths below. Do not open a public GitHub issue for security matters.
- PreferredGitHub Private Vulnerability Reporting →End-to-end encrypted, tracked, versioned. Best path if you already use GitHub.
- Email[email protected]Please include a reproducer, affected version(s), and a suggested severity.
What we commit to
- Acknowledge receipt within 3 business days.
- Provide an initial assessment within 10 business days.
- Coordinate a disclosure window that fits the severity and downstream user impact.
- Credit reporters in the advisory unless you prefer to remain anonymous.
Scope
In scope: the AuthPlane authorization server binary, the published SDKs (Python, TypeScript, Go), the marketing site (authplane.ai), and the docs (docs.authplane.ai).
Out of scope: findings that require physical access, social engineering, or a rooted client. Denial-of-service via automated fuzzing without a novel attack vector.
More context
The threat model, key-management practices, and DPoP posture are documented at docs.authplane.ai/security. Machine-readable disclosure metadata is at /.well-known/security.txt (RFC 9116).