Reporting Security Issues
Please do not report security vulnerabilities through public GitHub issues. Instead, please report them via email to security@windsurf.com Please include the following information in your report including as much technical detail as possible:- Type of issue (e.g., buffer overflow, SQL injection, cross-site scripting, etc.)
 - The location of the affected source code (if applicable)
 - Any special configuration required to reproduce the issue
 - Step-by-step instructions to reproduce the issue
 - Proof-of-concept or exploit code (if possible)
 - Impact of the issue, including how an attacker might exploit it
 - Any other relevant information
 
Public GPG Key
Policy
Windsurf follows the principle of Coordinated Vulnerability Disclosure.Safe Harbor
Windsurf supports safe harbor for security researchers who:- Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our services
 - Only interact with accounts you own or with explicit permission of the account holder
 - Do not exploit a security issue you discover for any reason other than testing
 - Report any vulnerability you’ve discovered promptly
 - Follow the guidelines outlined in this document