The Deployer
Product How it works Security Pricing Docs
Sign in Check a repo Start free ▸
Check a repo Product How it works Security Pricing Docs
Sign in Start free

Security

Vulnerability Disclosure Policy

Effective 19 September 2026 · Last updated 19 September 2026 · Contact hello@thedploy.com

We welcome good-faith reports that help us improve The Deployer's security. This page explains what to report, how to report it, and what you can expect from us.

On this page

  1. 1. Please report
  2. 2. Please do not
  3. 3. How to report
  4. 4. What you can expect from us
  5. 5. Good-faith research
  6. 6. Scope
  7. 7. Rewards

1. Please report

  • authentication bypass;
  • authorisation issues, including cross-tenant or cross-workspace access;
  • exposure of stored credentials or secrets;
  • ways to escalate the access The Deployer holds in a connected cloud account;
  • remote code execution, including through repository builds or the public repository check;
  • server-side request forgery;
  • injection;
  • serious business-logic issues with a security impact.

2. Please do not

  • access other customers' data beyond the minimum needed to demonstrate the issue, or keep it;
  • modify or destroy data;
  • run denial-of-service tests or high-volume automated scanning;
  • do anything that generates material cloud costs for us or anyone else;
  • use social engineering, phishing or physical attacks against our people or customers;
  • publicly disclose an issue before we have had a reasonable time to fix it.

Where you can, test against an account you created yourself.

3. How to report

Email hello@thedploy.com. Please include:

  • what the issue is and where it is (URL, endpoint or component);
  • step-by-step instructions to reproduce it;
  • what an attacker could do with it;
  • any proof-of-concept code, requests or screenshots;
  • how you would like to be credited, if at all.

Our contact details are also published in /.well-known/security.txt.

4. What you can expect from us

  • We will acknowledge your report within 5 business days.
  • We will keep you informed as we investigate and fix the issue.
  • We will let you know when it is fixed, and agree a disclosure timeline with you.
  • If you would like, we will credit you once the issue is fixed.

5. Good-faith research

If you make a good-faith effort to follow this policy, we will treat your research as authorised, work with you to understand and fix the issue, and not pursue or support legal action against you for it. If you are unsure whether something is allowed, ask us first at hello@thedploy.com.

6. Scope

In scope

  • thedploy.com, including the public repository check;
  • app.thedploy.com and portal.thedploy.com, including the API they use;
  • our MCP server package.

Out of scope

  • apps deployed with The Deployer and the cloud accounts they run in, which belong to our customers;
  • third-party services we use or connect to, such as cloud providers, code hosts, payment processors and email providers (please report to them directly);
  • social engineering;
  • denial of service and volumetric or high-rate automated scanning.

7. Rewards

We do not run a bug bounty programme at the moment, so we cannot offer payment for reports.

Security Terms of Service Privacy Policy Refund Policy Acceptable Use Subprocessors
The Deployer

Deploy and operate your app in your own cloud account, without building a DevOps platform yourself.

The Deployer is operated from India.

hello@thedploy.com

Product

Product How it works Cloud providers Migrations Launch Pricing Changelog

Resources

Documentation Free repo check Security Vulnerability disclosure Support Contact

Company

About Partner program Contact

Legal

Terms Privacy Refunds Acceptable Use Subprocessors
© 2026 The Deployer. All rights reserved. AWS, Google Cloud, Microsoft Azure, DigitalOcean, GitHub and other product names are trademarks of their respective owners. The Deployer is not affiliated with or endorsed by them.