Vulnerability Disclosure Policy
If you have found a security vulnerability in Stackbone, tell us. We will take it seriously, we will keep you informed, and we will not take legal action against you for reporting it in good faith.
Last updated · August 15, 2026
How to report
Email [email protected] with “Security” in the subject line.
Useful things to include: what the issue is, where you found it, the steps to reproduce it, what an attacker could do with it, and any proof of concept you have.
Please report in English or Spanish.
What we will do
- Acknowledge your report within 2 business days.
- Give you an initial assessment within 10 business days.
- Keep you updated while we work on it.
- Tell you when it is fixed.
- Credit you publicly when we publish the fix, if you want the credit.
What we ask of you
- Give us reasonable time to fix the issue before you tell anyone else. We suggest 90 days.
- Only test against accounts and data that belong to you.
- Do not access, modify or delete other people’s data.
- Do not degrade the service. No denial of service, no automated load testing, no spam.
- Do not use social engineering, phishing or physical attacks against our staff or offices.
- Delete any Stackbone data you obtained during your research once you have reported it.
Scope
In scope
- stackbone.ai and its subdomains
- The Stackbone control plane and API
- Our published SDKs and CLI
Out of scope
- Third-party services we use but do not control. Report those to the provider.
- Agent runtimes deployed in a customer’s own cloud account, where the misconfiguration belongs to that customer.
- Findings from automated scanners without a demonstrated, exploitable impact.
- Missing security headers, cookie flags or TLS configuration with no practical exploit.
- Rate limiting and brute force on endpoints with no sensitive effect.
- Social engineering, phishing and physical security.
- Self-inflicted issues that require the victim to paste code into a console or install software.
- Vulnerabilities in browsers or operating systems that are out of support.
Safe harbour
If you follow this policy in good faith, we will treat your research as authorised. We will not pursue or support legal action against you, and if a third party takes action against you for work that complied with this policy, we will make that clear.
This does not authorise you to break laws that apply to you regardless of our permission.
Rewards
We do not run a paid bug bounty programme. We do publicly credit researchers who report valid issues.