Security and vulnerability reports
Draft
This is a working draft for the developer-platform preview. It states current practice, not a contractual commitment, and will be replaced by a reviewed policy before general availability.
Report it here
developers@tango.vision — put "security" in the subject line.
That is the only reporting channel this site can promise reaches us. There is no bug-bounty programme, no separate disclosure portal, and no PGP key published today; if you need an encrypted channel, ask in a first mail without details and we will arrange one.
What helps
- What you found, and which host, endpoint or package it is in.
- The steps to reproduce it, and what you observed rather than what you infer.
- Whether you reached it from your own sandbox, from the public site, or from somewhere else.
- Whether anyone else's data was involved. If you believe it was, say so in the first line.
What we ask of you
- Test against your own sandbox, never against a customer tenant or the production shell. A sandbox is yours; a customer's building is not.
- Do not run load, denial-of-service or automated scanning against shared infrastructure — the cluster is shared (see On-demand sandboxes).
- Do not access, modify or keep data that is not yours. Stop at the point where you have shown the problem exists.
- Give us a reasonable chance to fix it before you publish.
Acting within these lines, in good faith, is not something we will treat as a breach of the Developer Terms of Service.
What to expect
We acknowledge reports by mail and tell you what we found. We do not commit to a fixed response time in this preview, and saying so is more useful than a number we have not measured. Serious issues are triaged ahead of everything else.
Not a security report
Broken links, wrong documentation, a failing build, a sandbox that will not provision — same address, no "security" in the subject.