Responsible Disclosure
We value the security community and prioritize the security of our systems. We encourage the responsible disclosure of security vulnerabilities to help us protect the security and privacy of our users and customers.
Reporting a Vulnerability
If you believe you have found a security vulnerability in Polyaxon, please send an actionable vulnerability report to [email protected].
Please include the following details in your report:
- A clear description of the vulnerability, including its potential impact.
- Steps to reproduce the vulnerability, including any specific configurations or conditions required.
- Any proof-of-concept code, scripts, or screenshots that demonstrate the vulnerability.
We take all disclosures very seriously, and once we receive a disclosure we rapidly verify each vulnerability before taking the necessary steps to fix it. Once verified, we periodically send status updates as problems are fixed.
We will acknowledge receipt of your report, typically within 2 business days, and will work with you to understand and resolve the issue.
Focus Areas
- Improper or missing authorization checks
- Insecure role assignments or privilege escalation
- Ability to access resources or perform actions outside assigned permissions, especially across organizations
Out of Scope
The following issues are considered out of scope and will not be accepted:
- Denial of Service (DoS) attacks, including volumetric attacks or repetitive API calls based on captured frontend calls
- Missing rate limiting without demonstrating a concrete security impact
- Automated scanner output without manual verification or a working proof of concept
- Missing security headers (e.g., CSP, X-Frame-Options) without a demonstrated exploit or missing Secure/HttpOnly flag on non-sensitive cookies
- Unsolicited messages Testing that would result in sending spam or other unsolicited messages to Polyaxon users
- Social engineering or phishing attacks against Polyaxon employees or users
Our Commitment
- We will investigate reported vulnerabilities promptly.
- We will keep you informed of our progress.
- We will take appropriate steps to remediate confirmed vulnerabilities.
- We will publicly acknowledge your contribution if you wish, once the vulnerability is fixed.
Bug Bounty Program
Please note that we currently do not operate a formal bug bounty program with monetary rewards.
Contact
For all security-related inquiries, including vulnerability disclosures, please contact [email protected].