Vulnerability disclosure policy
Alpacon is committed to ensuring the security of our platform and protecting our users. We welcome and appreciate security researchers and users who help us identify and address security vulnerabilities.
Safe harbor
Alpacon is committed to working with security researchers and will not pursue legal action against researchers who:
- Act in good faith to report security vulnerabilities
- Make a good faith effort to avoid privacy violations, data destruction, and service disruption
- Do not exploit vulnerabilities beyond what’s necessary to demonstrate them
- Follow this disclosure policy
Legal protection:
- We will not initiate legal action for vulnerability research conducted under this policy
- We will not report you to law enforcement for good-faith security research
- If legal action is initiated by a third party, we will take steps to make it known that your actions were conducted under this policy
Reporting a vulnerability
How to report
Email: security@alpacax.com
If you want to encrypt your report, ask us for our PGP key at the same address and we’ll send it.
What to include
Please provide as much information as possible:
- Description: Clear description of the vulnerability
- Impact: Potential security impact and severity assessment
- Steps to reproduce: Detailed steps to reproduce the issue
- Proof of concept: Code, screenshots, or video demonstrating the vulnerability (if applicable)
- Affected components: Which parts of Alpacon are affected (web app, agent, API, etc.)
- Your contact information: So we can follow up with questions
- Disclosure timeline: Your preferred disclosure timeline
Example report:
Subject: [Security] <one-line summary>
Description:
What the flaw is, in one or two sentences.
Impact:
Who can do what, and what they end up with. Say what an attacker needs
to start — an account, a role, a link the victim clicks, nothing at all.
Steps to reproduce:
1. ...
2. ...
3. What you observed, and what you expected instead.
Affected component: web app / API / agent / self-hosted distribution
Version and environment: <version>, <environment>
Contact: you@example.com
Preferred disclosure: 90 days
Our commitment
Response timeline
- Initial response: Within 48 hours of receiving your report
- Vulnerability assessment: Within 5 business days
- Resolution: Timeline depends on severity (see below)
If a vulnerability affected users, we notify them.
Severity-based resolution timeline
| Severity | Description | Target Resolution |
|---|---|---|
| Critical | Remote code execution, authentication bypass, data breach | 7 days |
| High | Privilege escalation, significant data exposure | 30 days |
| Medium | Information disclosure, denial of service | 60 days |
| Low | Minor security issues, configuration problems | 90 days |
A finding that bypasses a service limit or a billing control without exposing data or escalating privileges is rated on the impact it carries, usually Low.
Responsible disclosure
Disclosure timeline
We request that you:
- Coordinate disclosure timing with us
- Avoid exploiting the vulnerability beyond what’s necessary to demonstrate it
Whether we ask you to hold publication depends on severity:
| Severity | Do we ask you to wait? |
|---|---|
| Critical / High | Yes, until the fix is deployed |
| Medium | Yes, on a date we agree with you |
| Low | No |
Whatever the rating, we will ask you to wait if someone else’s data or account can be reached with the finding and they did nothing to invite it.
Where we do ask, the outer bound is 90 days from your initial report for Critical and High, 120 days for Medium. We’re open to adjusting either.
Public disclosure
After a fix is released, we support coordinated public disclosure:
- CVE assignment: for the self-hosted distribution only. The hosted service has no version for you to upgrade, so nothing to identify.
- Release notes: we describe the fix in the notes for the version carrying it
- Blog post: For significant vulnerabilities, we may publish a detailed writeup
- Your writeup: You’re welcome to publish your own technical writeup after disclosure
Scope
In scope
Infrastructure & applications:
*.alpacon.ioand*.alpacax.com(every host we run on either domain)- Alpacon web application (browser-based)
- Alpacon CLI tool
- Alpamon agent software
- Public APIs and endpoints
Vulnerability types:
- Authentication and authorization bypasses
- Remote code execution
- SQL injection, NoSQL injection
- Cross-site scripting (XSS)
- Cross-site request forgery (CSRF)
- Server-side request forgery (SSRF)
- Insecure direct object references (IDOR)
- Security misconfigurations
- Sensitive data exposure
- XML external entity (XXE) attacks
- Deserialization vulnerabilities
- Business logic flaws with security impact
Out of scope
Excluded domains & assets:
- Anything a vendor operates, including on a host under our own domains, and any third-party service we use (AWS and the like) — report those to the vendor
- Employee email accounts
- Archived or deprecated services
Excluded vulnerability types:
- Running DoS/DDoS attacks against our infrastructure. A flaw that lets someone deny service is in scope; demonstrate it without actually doing it
- Social engineering attacks against Alpacon employees
- Physical attacks against Alpacon offices or data centers
- Spam or phishing attacks
- Vulnerabilities in outdated browsers or platforms
- Issues that require physical access to a user’s device
Non-security issues:
- Bugs that don’t have security impact
- Feature requests
- Usability issues
- Performance issues that do not enable denial of service
Hygiene findings on our static marketing and documentation sites are in scope and worth sending, but we handle them as informational: you get an answer, and we close them without a remediation target.
Recognition
Credit
For a valid finding that is the first report of that issue, we credit you when we announce the fix. Tell us how you would like to be named.
Opt-out: If you prefer to remain anonymous, we’ll respect your wishes.
Monetary rewards
We do not currently offer monetary rewards.
Contact
Everything on this page goes to one address: security@alpacax.com. PGP available on request.
If you believe a vulnerability is being actively exploited right now, put
[ACTIVE EXPLOITATION] at the front of the subject line so it is triaged ahead
of the queue.
For security questions that are not vulnerability reports, support@alpacax.com will route you.
Additional resources
- Security overview — our overall security approach
- Security FAQ — frequently asked security questions
- Privacy policy — how we handle data
Policy updates
This policy may be updated from time to time. The version and date below tell you which one you are reading.
Current version: 1.1 Last updated: August 2026 Next review: February 2027
Thank you for helping keep Alpacon and our users safe!