Akkento Pty Ltd regards the security of Hyperlane, and of the people and organisations who depend on it, as a fundamental responsibility.
If you have found a security vulnerability in Hyperlane, we would like to hear from you. Reporting it responsibly protects everyone who uses Hyperlane, and every report is taken seriously. This policy sets out how to reach us, what we will do in response, and the protections we extend to those who report in good faith.
Please email security@hyperlaneide.com.
We ask that reports reach us privately in the first instance, rather than through public issues, discussions, or pull requests. Private disclosure allows a fix to be prepared and distributed before details become available to those who would misuse them, which protects users in the interim. We appreciate your discretion in this.
Where possible, please submit one report per vulnerability.
The following details assist us in validating and resolving a report. We appreciate that not all of them will be available in every case, and we would rather receive a partial report than none at all.
- A description of the vulnerability and the security impact you consider it to carry
- The affected component, and the Hyperlane version shown under Help → About
- The operating system and configuration on which the issue was observed
- Steps to reproduce, a proof of concept, or a short recording
- Any relevant logs, stack traces, or crash output, with your own credentials removed
- Your assessment of the severity, if you have formed one
- Whether the issue is already public or known to other parties
- How you wish to be credited, or confirmation that you prefer to remain anonymous
This repository distributes Hyperlane and hosts its issue tracker. The editor source is developed privately.
In scope
- The Hyperlane application on Windows, macOS, and Linux
- The installers, archives, and updates published to this repository
- The update mechanism, including the integrity of published artifacts
- The handling of credentials, tokens, and agent transport within the application
Out of scope
- Vulnerabilities in upstream Code - OSS that Hyperlane inherits without modification. These require a fix from Microsoft before we can carry it. We would still welcome a copy of your report so that we can track its progress.
- Vulnerabilities in extensions, coding agents, or model providers that you have installed or connected yourself. These are best reported to the parties who maintain them.
- Findings that require an attacker to already control the machine
- Automated scanner output submitted without a demonstrated security impact
- Social engineering of our personnel, physical attacks, and denial of service through volume of traffic
On receipt of a report, we will do the following.
- Acknowledge that your report has been received and read, as promptly as we are able
- Investigate the issue, work to reproduce it, and assess its severity
- Keep you informed of our progress, and let you know our assessment and our intended course of action
- Develop and release a fix, prioritised according to the severity and impact of the issue
We treat the most serious vulnerabilities, such as those permitting remote code execution or the theft of credentials, with the greatest urgency, and will issue an out-of-band release where one is warranted. We do not commit to fixed timeframes, as the time required depends on the nature and complexity of the issue, but we will act without undue delay and will keep you updated throughout.
We ask that you give us a reasonable opportunity to investigate and address an issue before publishing any details of it. We are glad to coordinate the timing of any announcement with you, and to do so once a fix has shipped and users have had a fair opportunity to update.
We will work with you on the timing of disclosure rather than impose it, and we will not ask you to withhold a finding indefinitely.
Not every issue calls for a public announcement. Where we determine that a vulnerability warrants an advisory, we will publish one, and where we do, we will credit the reporter by name unless anonymity is requested.
We welcome reports from anyone who discovers a security vulnerability in Hyperlane, and we want working with us to be straightforward. This section explains the protection that applies when you report in good faith.
We will not pursue or support legal action against someone who reports a genuine vulnerability to us in good faith, provided they have acted responsibly in doing so. Acting responsibly means, among other things, keeping any testing to your own installation and your own accounts, leaving other people's data and other people's access untouched, not disrupting or interrupting the normal running of our services, stopping at the point a vulnerability becomes apparent rather than pressing further, and keeping what you have found in confidence until we have had a fair opportunity to address it.
This protection concerns Hyperlane and our own systems only. It does not extend to the systems, services, or data of any third party, including the extension registries, coding agents, and model providers that Hyperlane connects to.
Nothing in this policy limits the rights of others or overrides Australian law.
Personal information contained in your report is handled in accordance with our Privacy Policy.
Where a vulnerability has exposed personal information, we assess the incident promptly and take reasonable steps to contain it and to protect the individuals affected.
We retain reports for as long as is necessary to remediate the issue and to meet our legal obligations.
Hyperlane is in alpha and releases frequently. Security fixes are provided for the latest release only, and are delivered in the next build rather than backported to earlier versions. Hyperlane updates itself, and accepting the update prompt is ordinarily sufficient to remain current.
We do not currently operate a paid bug bounty. Where we publish an advisory for a vulnerability, we credit the reporter by name unless anonymity is requested. The work involved in identifying a vulnerability and reporting it responsibly is considerable, and we are grateful for it.
| For | Contact |
|---|---|
| Security reports | security@hyperlaneide.com |
| Privacy enquiries and complaints | See the Privacy Policy at hyperlaneide.com |
Thank you for helping to keep Hyperlane and its users safe. We appreciate the care that goes into finding and reporting a vulnerability responsibly.