Security
Report a vulnerability
Report a potential security issue affecting Easel.
Report suspected vulnerabilities privately so the Easel security team can investigate before public disclosure.
What to include
Include:
- A clear description
- Affected product or endpoint
- Reproduction steps
- Proof-of-concept requests or code
- Security impact
- Preconditions
- Relevant account, workspace, project, deployment, or request IDs
- Whether customer data may be affected
- Your preferred contact information
Do not include customer secrets or unrelated personal data.
Contact
Email:
Do not post vulnerabilities in community channels. Easel acknowledges reports promptly and coordinates disclosure with you.
Research guidelines
When testing:
- Stay within systems you are authorized to assess
- Avoid denial-of-service testing against production
- Do not access or exfiltrate customer data
- Do not use social engineering against Easel staff or customers
- Give Easel reasonable time to investigate before public disclosure
Account compromise
For suspected account compromise:
- Revoke active sessions.
- Rotate API tokens.
- Rotate exposed application secrets.
- Review workspace members.
- Contact support or
security@easel.sh.