Skip to main content
Security

Report a vulnerability

Report a potential security issue affecting Easel.

Report suspected vulnerabilities privately so the Easel security team can investigate before public disclosure.

What to include

Include:

  • A clear description
  • Affected product or endpoint
  • Reproduction steps
  • Proof-of-concept requests or code
  • Security impact
  • Preconditions
  • Relevant account, workspace, project, deployment, or request IDs
  • Whether customer data may be affected
  • Your preferred contact information

Do not include customer secrets or unrelated personal data.

Contact

Email:

security@easel.sh

Do not post vulnerabilities in community channels. Easel acknowledges reports promptly and coordinates disclosure with you.

Research guidelines

When testing:

  • Stay within systems you are authorized to assess
  • Avoid denial-of-service testing against production
  • Do not access or exfiltrate customer data
  • Do not use social engineering against Easel staff or customers
  • Give Easel reasonable time to investigate before public disclosure

Account compromise

For suspected account compromise:

  1. Revoke active sessions.
  2. Rotate API tokens.
  3. Rotate exposed application secrets.
  4. Review workspace members.
  5. Contact support or security@easel.sh.

On this page

Edit on GitHub