Security and Vulnerability Disclosure
Last updated 6 October 2026
Updawg decides what gets installed on other people's servers, so we take reports about its security seriously and would much rather hear about a problem from you than from an attacker. This page says how to report one, what we commit to in return, and the rules that keep your research on the right side of our terms.
How Updawg is built to make attacks hard in the first place, from signed jobs to the isolated signer, is in our security whitepaper.
How to report
Email security@updawg.net. Please include:
- what you found and where (a URL, endpoint, or agent version);
- steps to reproduce it, or a proof of concept;
- what an attacker could do with it, as you understand it;
- how you would like to be credited, if at all.
The same address is listed in our security.txt. Please don't report vulnerabilities through public GitHub issues.
What we commit to
- Acknowledgement within 3 working days that a person has read your report.
- An assessment within 10 working days: whether we can reproduce it, how severe we think it is, and what happens next.
- A fix, or a mitigation, within 7 days for critical issues, 30 days for high, and 90 days for everything else, counted from when we confirm the problem. If we can't meet that, we will tell you why and when.
- Updates as the fix progresses, and a note when it ships.
- Credit in the release notes or advisory, under the name you give us, unless you ask us not to.
We do not run a paid bug bounty. If that changes, it will be announced here.
Coordinated disclosure
Please give us the chance to fix a problem before you publish it. We ask for 90 days from your report, or until a fix has shipped, whichever comes first. If a problem is being actively exploited, we may publish sooner, and we will agree the timing with you where we can.
Safe harbour
If you act in good faith and follow the rules on this page, we consider your research authorised, we will not take legal action against you or ask anyone else to, and we will treat it as permitted under our terms. If somebody else brings a claim over research that followed this policy, we will make it known that it was authorised.
Good faith means that you:
- test only against accounts, organizations and hosts that you own or have permission to use. A Free organization is enough for almost everything;
- stop as soon as you reach data that isn't yours, don't keep or share it, and tell us what you saw;
- do no more than you need to show the problem. Don't pivot, persist, or push changes to other people's hosts;
- don't degrade the service for others: no denial of service, no load testing, and keep automated scanning to a polite rate;
- keep the details confidential until the problem is fixed or the 90 days have passed.
In scope
- updawg.net, app.updawg.net (the portal) andapi.updawg.net (the API)
- agents.updawg.net, the gateway hosts connect to, and theupdawg agent itself, including its self-update and the signatures it checks
- pkg.updawg.net and get.updawg.net: the packages, the installer and the signed release manifests
- docs.updawg.net
- The Terraform provider, Pez-Solutions/terraform-provider-updawg
We most want to hear about anything that could let someone reach another organization's data, run a job or install a package on a host that nobody approved, or get the agent to accept something we didn't sign.
Out of scope
- Denial of service, volumetric or rate-limit testing, and spam or social engineering against our staff or customers
- Physical attacks on, or access to, anybody's premises or devices
- Services we use but don't run: Stripe, GitHub, Google, Microsoft, Apple and our hosting providers. Please report to them directly
- Findings with no practical impact on their own: missing headers or cookie flags, clickjacking on pages with no actions, self-XSS, version banners, email SPF, DKIM or DMARC configuration, and unedited output from automated scanners
- Problems that require an already-compromised host, browser or account with full access, unless Updawg makes the situation meaningfully worse
Not sure whether something counts? Report it anyway. We would rather read one report too many.