2020-03-20 06:30:10 +01:00
# Security Policy
2026-06-10 13:53:26 +02:00
## Reporting Security Issues
2020-03-20 06:30:10 +01:00
2026-06-10 13:53:26 +02:00
We take the security of ZITADEL very seriously. If you believe you have found a security vulnerability in ZITADEL, we encourage you to report it to us immediately.
2020-03-20 06:30:10 +01:00
2026-06-10 13:53:26 +02:00
**Please do not report security-related findings publicly via GitHub issues.** Public disclosure of a security vulnerability could put the ZITADEL community at risk. Instead, please use our official vulnerability disclosure process.
2023-03-16 09:52:12 +02:00
2026-06-10 13:53:26 +02:00
### Vulnerability Disclosure Process
2023-03-16 09:52:12 +02:00
2026-06-10 13:53:26 +02:00
Vulnerabilities should be reported through our dedicated portal:
** [zitadel.com/vulnerability ](https://zitadel.com/vulnerability )**
2023-03-16 09:52:12 +02:00
2026-06-10 13:53:26 +02:00
For more details on our vulnerability policy, including scope and expectations, please refer to our official policy document:
** [ZITADEL Vulnerability Disclosure Policy ](https://trust.zitadel.com/resources?s=aw085mxrel3icmbmkphns3&name=zitadel-vulnerability-disclosure-policy )**
2023-03-16 09:52:12 +02:00
2026-06-10 13:53:26 +02:00
### Definitive Source
2023-03-16 09:52:12 +02:00
2026-06-10 13:53:26 +02:00
When in doubt, the authoritative and most up-to-date source for our security reporting information is always our `security.txt` file:
** [zitadel.com/.well-known/security.txt ](https://zitadel.com/.well-known/security.txt )**
2026-03-20 09:23:25 +01:00
2026-06-10 13:53:26 +02:00
---
2026-03-20 09:23:25 +01:00
2026-06-10 13:53:26 +02:00
We appreciate your help in keeping ZITADEL and its community safe!