Security
Reporting a security issue
Datacoves is a managed dbt and Airflow platform, available as SaaS and as a private deployment inside a customer's own cloud. We also run Atlas, a hosted self-service analytics product. If you have found a security issue in either, in our published code, or in anything else we run, we want to hear from you.
Email security@datacoves.com.
Please include:
- - Which system, repository, package version, or component is affected
- - What the issue is, and why you think it matters
- - Steps to reproduce, or a proof of concept
- - Anything we should be careful about when we reproduce it
If the issue is in one of our public GitHub repositories, you can also use GitHub's private vulnerability reporting from the Security tab of that repository. Please do not open a public issue or pull request for a security problem.
What you can expect from us
- - We will acknowledge your report within 3 business days.
- - We will tell you whether we have reproduced it, and give you a rough timeline, within 10 business days.
- - We will keep you updated while we work on a fix, and let you know when it ships.
We do not run a paid bug bounty program. We may offer a discretionary award for reports that lead to a meaningful fix, but please do not treat that as a commitment.
Full policy
A complete policy covering scope, testing guidelines, and safe harbor terms is being finalized and will be published on this page shortly. In the meantime, please get in touch at the address above before beginning any testing, and we will tell you what is in scope.