Security

Responsible disclosure

Reporting a vulnerability

If you believe you've found a security issue in AuthPlane — the authorization server, any SDK, or this website — please report it via one of the paths below. Do not open a public GitHub issue for security matters.

What we commit to

  • Acknowledge receipt within 3 business days.
  • Provide an initial assessment within 10 business days.
  • Coordinate a disclosure window that fits the severity and downstream user impact.
  • Credit reporters in the advisory unless you prefer to remain anonymous.

Scope

In scope: the AuthPlane authorization server binary, the published SDKs (Python, TypeScript, Go), the marketing site (authplane.ai), and the docs (docs.authplane.ai).

Out of scope: findings that require physical access, social engineering, or a rooted client. Denial-of-service via automated fuzzing without a novel attack vector.

More context

The threat model, key-management practices, and DPoP posture are documented at docs.authplane.ai/security. Machine-readable disclosure metadata is at /.well-known/security.txt (RFC 9116).