Security
Reporting a security problem
If you found a way into something that is not yours on klickops, tell us privately first. We look at every report.
How to report
Email info@natron.io with "Security" in the subject. Include what you found, where (the page, feature or address), the steps to reproduce it, and what someone could do with it. Keep the details out of public places, including support requests and issue trackers, until the fix is live.
While you look, please:
- use your own account and organization, and stop at the first sign of someone else's data;
- not degrade the service for others: no load tests, floods or destructive changes;
- not use social engineering or anything physical.
What happens next
- We read every report and get in touch if we need more from you.
- If you want to be named, we can credit you in the release notes when a fix ships.
How fixes are published
We describe security fixes in the release notes, under Security: how severe it was, what was at risk, what we checked for misuse, and what you need to do, if anything. The notes never describe how to reach the hole.
Not in scope
- denial of service and volume-based attacks;
- reports from automated scanners without a demonstrated impact;
- missing headers or best practices without a way to exploit them;
- services we do not run, even when klickops links to them.