Vulnerability disclosure policy

Alpacon is committed to ensuring the security of our platform and protecting our users. We welcome and appreciate security researchers and users who help us identify and address security vulnerabilities.

Safe harbor

Alpacon is committed to working with security researchers and will not pursue legal action against researchers who:

  1. Act in good faith to report security vulnerabilities
  2. Make a good faith effort to avoid privacy violations, data destruction, and service disruption
  3. Do not exploit vulnerabilities beyond what’s necessary to demonstrate them
  4. Follow this disclosure policy

Legal protection:

  • We will not initiate legal action for vulnerability research conducted under this policy
  • We will not report you to law enforcement for good-faith security research
  • If legal action is initiated by a third party, we will take steps to make it known that your actions were conducted under this policy

Reporting a vulnerability

How to report

Email: security@alpacax.com

If you want to encrypt your report, ask us for our PGP key at the same address and we’ll send it.

What to include

Please provide as much information as possible:

  1. Description: Clear description of the vulnerability
  2. Impact: Potential security impact and severity assessment
  3. Steps to reproduce: Detailed steps to reproduce the issue
  4. Proof of concept: Code, screenshots, or video demonstrating the vulnerability (if applicable)
  5. Affected components: Which parts of Alpacon are affected (web app, agent, API, etc.)
  6. Your contact information: So we can follow up with questions
  7. Disclosure timeline: Your preferred disclosure timeline

Example report:

Subject: [Security] <one-line summary>

Description:
What the flaw is, in one or two sentences.

Impact:
Who can do what, and what they end up with. Say what an attacker needs
to start — an account, a role, a link the victim clicks, nothing at all.

Steps to reproduce:
1. ...
2. ...
3. What you observed, and what you expected instead.

Affected component: web app / API / agent / self-hosted distribution
Version and environment: <version>, <environment>

Contact: you@example.com
Preferred disclosure: 90 days

Our commitment

Response timeline

  • Initial response: Within 48 hours of receiving your report
  • Vulnerability assessment: Within 5 business days
  • Resolution: Timeline depends on severity (see below)

If a vulnerability affected users, we notify them.

Severity-based resolution timeline

SeverityDescriptionTarget Resolution
CriticalRemote code execution, authentication bypass, data breach7 days
HighPrivilege escalation, significant data exposure30 days
MediumInformation disclosure, denial of service60 days
LowMinor security issues, configuration problems90 days

A finding that bypasses a service limit or a billing control without exposing data or escalating privileges is rated on the impact it carries, usually Low.

Responsible disclosure

Disclosure timeline

We request that you:

  1. Coordinate disclosure timing with us
  2. Avoid exploiting the vulnerability beyond what’s necessary to demonstrate it

Whether we ask you to hold publication depends on severity:

SeverityDo we ask you to wait?
Critical / HighYes, until the fix is deployed
MediumYes, on a date we agree with you
LowNo

Whatever the rating, we will ask you to wait if someone else’s data or account can be reached with the finding and they did nothing to invite it.

Where we do ask, the outer bound is 90 days from your initial report for Critical and High, 120 days for Medium. We’re open to adjusting either.

Public disclosure

After a fix is released, we support coordinated public disclosure:

  • CVE assignment: for the self-hosted distribution only. The hosted service has no version for you to upgrade, so nothing to identify.
  • Release notes: we describe the fix in the notes for the version carrying it
  • Blog post: For significant vulnerabilities, we may publish a detailed writeup
  • Your writeup: You’re welcome to publish your own technical writeup after disclosure

Scope

In scope

Infrastructure & applications:

  • *.alpacon.io and *.alpacax.com (every host we run on either domain)
  • Alpacon web application (browser-based)
  • Alpacon CLI tool
  • Alpamon agent software
  • Public APIs and endpoints

Vulnerability types:

  • Authentication and authorization bypasses
  • Remote code execution
  • SQL injection, NoSQL injection
  • Cross-site scripting (XSS)
  • Cross-site request forgery (CSRF)
  • Server-side request forgery (SSRF)
  • Insecure direct object references (IDOR)
  • Security misconfigurations
  • Sensitive data exposure
  • XML external entity (XXE) attacks
  • Deserialization vulnerabilities
  • Business logic flaws with security impact

Out of scope

Excluded domains & assets:

  • Anything a vendor operates, including on a host under our own domains, and any third-party service we use (AWS and the like) — report those to the vendor
  • Employee email accounts
  • Archived or deprecated services

Excluded vulnerability types:

  • Running DoS/DDoS attacks against our infrastructure. A flaw that lets someone deny service is in scope; demonstrate it without actually doing it
  • Social engineering attacks against Alpacon employees
  • Physical attacks against Alpacon offices or data centers
  • Spam or phishing attacks
  • Vulnerabilities in outdated browsers or platforms
  • Issues that require physical access to a user’s device

Non-security issues:

  • Bugs that don’t have security impact
  • Feature requests
  • Usability issues
  • Performance issues that do not enable denial of service

Hygiene findings on our static marketing and documentation sites are in scope and worth sending, but we handle them as informational: you get an answer, and we close them without a remediation target.

Recognition

Credit

For a valid finding that is the first report of that issue, we credit you when we announce the fix. Tell us how you would like to be named.

Opt-out: If you prefer to remain anonymous, we’ll respect your wishes.

Monetary rewards

We do not currently offer monetary rewards.

Contact

Everything on this page goes to one address: security@alpacax.com. PGP available on request.

If you believe a vulnerability is being actively exploited right now, put [ACTIVE EXPLOITATION] at the front of the subject line so it is triaged ahead of the queue.

For security questions that are not vulnerability reports, support@alpacax.com will route you.

Additional resources

Policy updates

This policy may be updated from time to time. The version and date below tell you which one you are reading.

Current version: 1.1 Last updated: August 2026 Next review: February 2027


Thank you for helping keep Alpacon and our users safe!

Last updated: