Skip to content

Security: PatterAI/Patter

Security

SECURITY.md

Security Policy

Reporting a Vulnerability

If you discover a security vulnerability in Patter, please report it responsibly.

Email: security@getpatter.com

Please include:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Suggested fix (if any)

Response Timeline

  • Acknowledgment: within 48 hours
  • Initial assessment: within 7 days
  • Fix timeline: within 90 days (critical issues prioritized)

Scope

We are interested in vulnerabilities related to:

  • Authentication and authorization bypass
  • API key or credential exposure
  • Injection attacks (SQL, command, prompt)
  • SSRF or webhook security issues
  • Telephony abuse (toll fraud, caller ID spoofing)
  • Cross-site scripting (XSS) in the dashboard

Out of Scope

  • Feature requests (use GitHub Issues)
  • General bugs that do not have a security impact
  • Social engineering attacks
  • Denial of service (DoS) attacks

Disclosure

We follow coordinated disclosure. Please do not publicly disclose vulnerabilities until we have released a fix and notified affected users.

There aren't any published security advisories