Skip to content

Security and vulnerability reports

Draft

This is a working draft for the developer-platform preview. It states current practice, not a contractual commitment, and will be replaced by a reviewed policy before general availability.

Report it here

developers@tango.vision — put "security" in the subject line.

That is the only reporting channel this site can promise reaches us. There is no bug-bounty programme, no separate disclosure portal, and no PGP key published today; if you need an encrypted channel, ask in a first mail without details and we will arrange one.

What helps

  • What you found, and which host, endpoint or package it is in.
  • The steps to reproduce it, and what you observed rather than what you infer.
  • Whether you reached it from your own sandbox, from the public site, or from somewhere else.
  • Whether anyone else's data was involved. If you believe it was, say so in the first line.

What we ask of you

  • Test against your own sandbox, never against a customer tenant or the production shell. A sandbox is yours; a customer's building is not.
  • Do not run load, denial-of-service or automated scanning against shared infrastructure — the cluster is shared (see On-demand sandboxes).
  • Do not access, modify or keep data that is not yours. Stop at the point where you have shown the problem exists.
  • Give us a reasonable chance to fix it before you publish.

Acting within these lines, in good faith, is not something we will treat as a breach of the Developer Terms of Service.

What to expect

We acknowledge reports by mail and tell you what we found. We do not commit to a fixed response time in this preview, and saying so is more useful than a number we have not measured. Serious issues are triaged ahead of everything else.

Not a security report

Broken links, wrong documentation, a failing build, a sandbox that will not provision — same address, no "security" in the subject.

Built on the Tango Vision platform. Questions? developers@tango.vision