Reporting Security Issues
Please do not report security vulnerabilities through public GitHub issues. Instead, please report them via email to security@windsurf.com Please include the following information in your report including as much technical detail as possible:- Type of issue (e.g., buffer overflow, SQL injection, cross-site scripting, etc.)
- The location of the affected source code (if applicable)
- Any special configuration required to reproduce the issue
- Step-by-step instructions to reproduce the issue
- Proof-of-concept or exploit code (if possible)
- Impact of the issue, including how an attacker might exploit it
- Any other relevant information
Public GPG Key
Policy
Windsurf follows the principle of Coordinated Vulnerability Disclosure.Safe Harbor
Windsurf supports safe harbor for security researchers who:- Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our services
- Only interact with accounts you own or with explicit permission of the account holder
- Do not exploit a security issue you discover for any reason other than testing
- Report any vulnerability you’ve discovered promptly
- Follow the guidelines outlined in this document