Skip to content

Latest commit

 

History

History
28 lines (16 loc) · 1.18 KB

File metadata and controls

28 lines (16 loc) · 1.18 KB

Security Policy

Reporting a vulnerability

Please report suspected vulnerabilities privately to security@pipefy.com (or via Pipefy’s security page). Do not open public GitHub issues for security reports.

When available, you may also use GitHub Private Vulnerability Reporting (Security → Report a vulnerability on this repository).

Include:

  • Affected component (MCP server / CLI / SDK / skill)
  • Version or commit
  • Reproduction steps
  • Impact assessment

We aim to acknowledge reports within 2 business days and to provide a remediation plan or status within 10 business days.

Scope

This policy covers the code in this repository. Vulnerabilities in the Pipefy platform itself should be reported through the channels listed at https://www.pipefy.com/security/.

Supported versions

Only the latest release line receives security fixes during the pre-1.0 beta.

Safe harbor

We will not pursue legal action against good-faith security research that respects user privacy, avoids data destruction or service degradation, and gives us reasonable time to remediate before public disclosure.