---
title: "Reporting a vulnerability"
description: "Report a security problem in Outpost privately by email. What to include, and what happens after you send it."
url: "https://support.outpostplatform.com/security/reporting-a-vulnerability/"
product: "platform"
type: "how-to"
status: "stub"
ai_summary: "How to report a security vulnerability in Outpost. Report privately by email to security@outpostplatform.com rather than in a public issue. States what to include, the response times to expect, what is in and out of scope, and the safe harbour for good faith research."
source: "https://gitlab.com/outpostplatform/docs/-/edit/main/src/content/docs/security/reporting-a-vulnerability.md"
license: "CC BY 4.0"
---

# Reporting a vulnerability

If you have found a security problem in Outpost, email
[security@outpostplatform.com](mailto:security@outpostplatform.com) rather than
opening a public issue. Include the component and version, what an attacker
gets, and how to reproduce it. You will get an acknowledgement within three
working days. This page is for security researchers, and for customers whose
own testing found something.

<!-- TODO: write this page against the how-to template.

Sections:

- Where to send it, and the fact that no encryption and no account is needed.
- What to include, as a checklist.
- What happens next, as a timeline with real numbers on it.
- Scope: which components and which deployments.
- Out of scope, so nobody spends a weekend on something we will close.
- Safe harbour for research that stays inside the scope above.
- Credit in the release note, and how to decline it.
- The absence of a paid bug bounty, said once and clearly.
- The machine readable version at /.well-known/security.txt.
-->

Follow the [how-to template](https://gitlab.com/outpostplatform/docs/-/blob/main/templates/how-to.md).
