Security
policy.
Security matters when your agents run against your codebase. Here is how to report a vulnerability in Astrivya — whether in the open-source packages or the cloud workspace.
Security matters when your agents run against your codebase. Here is how to report a vulnerability in Astrivya — whether in the open-source packages or the cloud workspace.
Send details to security@astrivya.ai instead of opening a public issue. Include the package, version, a minimal reproduction, and impact.
We acknowledge reports within 3 business days and keep you updated as we triage. You'll be credited once the fix ships.
We won't disclose a report before a fix is released. In return, we ask you to hold off public disclosure for 60 days from confirmation.
The astrivya open-source packages (akg-core, akg-indexer, mcp-server, cli, atlas, plugin-api, plugin-runtime), the MCP server implementation, and the Astrivya cloud workspace at app.astrivya.ai.
Out of scope: supply-chain noise (unaudited third-party dependencies), phishing of Astrivya users, and issues already documented in the public tracker. For anything else, write to us before going public.