Security
Vulnerability Disclosure Policy
We welcome good-faith reports that help us improve The Deployer's security. This page explains what to report, how to report it, and what you can expect from us.
1. Please report
- authentication bypass;
- authorisation issues, including cross-tenant or cross-workspace access;
- exposure of stored credentials or secrets;
- ways to escalate the access The Deployer holds in a connected cloud account;
- remote code execution, including through repository builds or the public repository check;
- server-side request forgery;
- injection;
- serious business-logic issues with a security impact.
2. Please do not
- access other customers' data beyond the minimum needed to demonstrate the issue, or keep it;
- modify or destroy data;
- run denial-of-service tests or high-volume automated scanning;
- do anything that generates material cloud costs for us or anyone else;
- use social engineering, phishing or physical attacks against our people or customers;
- publicly disclose an issue before we have had a reasonable time to fix it.
Where you can, test against an account you created yourself.
3. How to report
Email hello@thedploy.com. Please include:
- what the issue is and where it is (URL, endpoint or component);
- step-by-step instructions to reproduce it;
- what an attacker could do with it;
- any proof-of-concept code, requests or screenshots;
- how you would like to be credited, if at all.
Our contact details are also published in /.well-known/security.txt.
4. What you can expect from us
- We will acknowledge your report within 5 business days.
- We will keep you informed as we investigate and fix the issue.
- We will let you know when it is fixed, and agree a disclosure timeline with you.
- If you would like, we will credit you once the issue is fixed.
5. Good-faith research
If you make a good-faith effort to follow this policy, we will treat your research as authorised, work with you to understand and fix the issue, and not pursue or support legal action against you for it. If you are unsure whether something is allowed, ask us first at hello@thedploy.com.
6. Scope
In scope
- thedploy.com, including the public repository check;
- app.thedploy.com and portal.thedploy.com, including the API they use;
- our MCP server package.
Out of scope
- apps deployed with The Deployer and the cloud accounts they run in, which belong to our customers;
- third-party services we use or connect to, such as cloud providers, code hosts, payment processors and email providers (please report to them directly);
- social engineering;
- denial of service and volumetric or high-rate automated scanning.
7. Rewards
We do not run a bug bounty programme at the moment, so we cannot offer payment for reports.