Vulnerability Disclosure Policy
Last updated: 2026-08-28
MisterShell sits on the privileged-access path to your infrastructure, so we want to hear about security weaknesses in it as early as possible. This policy explains what is in scope, how to reach us, and what you can expect from us when you do. It is written for security researchers and for the security teams of organizations that run MisterShell.
1. Scope
The following are in scope:
- MisterShell software: the Core, Workers, Sensors, and Session Proxies, in any supported deployment topology.
- The official MisterShell Terraform provider.
- This website, mistershell.com, and the support portal at mistershell.zohodesk.eu.
The following are out of scope:
- The infrastructure a MisterShell installation runs on — your hosts, network, database, cache, object store, identity provider, and LLM endpoints are yours to secure.
- Third-party model providers and any data you choose to send them.
- Denial-of-service or volumetric testing of any kind.
- Social engineering, phishing, or physical attacks against MisterShell staff or users.
- Findings that require a compromised administrator account or physical access to reproduce, unless they defeat a control MisterShell specifically claims to enforce.
If you are unsure whether something is in scope, report it anyway and say so — we would rather triage a borderline report than miss a real one.
2. How to report
Email security@mistershell.com. This address is for security reports
only; for anything else, see section 9. A machine-readable copy of this contact is
published at /.well-known/security.txt.
We do not currently publish a PGP key. If your report contains sensitive details, tell us in a first message and we will arrange a secure channel before you send them.
3. What to include
Reports that let us reproduce the issue quickly get fixed quickly. Please include:
- The component affected (Core, Worker, Sensor, Proxy, Terraform provider, website) and its version.
- Step-by-step reproduction, with requests, commands, or configuration where relevant.
- Your assessment of the impact — what an attacker gains, and what they need to start with.
- Whether the issue has been disclosed anywhere else, and how you would like to be credited, if at all.
4. What we commit to
- Acknowledgement within 3 business days of receiving your report.
- A named contact who keeps you informed as we triage, reproduce, and fix.
- Fix targets by severity, measured from confirmation: critical, 7 days; high, 30 days; medium and low, 90 days. If we cannot meet a target, we will tell you why and what the revised date is.
- Credit in the release that ships the fix, if you want it.
5. Coordinated disclosure
We ask that you give us the opportunity to fix a vulnerability before you publish it, and that you do not share it with third parties in the meantime. We will not ask you to withhold publication indefinitely: once a fix is released, or 90 days after confirmation, whichever comes first, you are free to publish. We are happy to agree on a joint disclosure date.
6. Safe harbor
If you make a good-faith effort to comply with this policy, we will not pursue or support legal action against you for your research. Good faith means you act within the scope above, avoid privacy violations, data destruction, and service disruption, do not access or retain data beyond what is needed to demonstrate the issue, and give us reasonable time to respond before disclosing.
Test against your own MisterShell installation. Do not test against installations you do not own or are not authorized to test.
7. No bug bounty
We do not run a bug bounty program and do not pay for reports today. We say so plainly so that nobody is surprised. What we do offer is a responsive, technical counterpart who will take your report seriously and credit your work.
8. How fixes reach you
Security fixes ship in regular MisterShell releases. When a report leads to a fix, we tell the reporter which version contains it and describe the issue in that release's notes. We do not currently operate a security-advisory mailing list and are not a CVE numbering authority; where a report warrants a CVE, we will work with the reporter to request one.
MisterShell never phones home, so it cannot notify your installation of a fix. Keep an eye on releases and upgrade promptly.
9. Everything else
For product questions, bugs that have no security impact, licensing, and deployment help, use the support portal at mistershell.zohodesk.eu. Privacy questions go to privacy@mistershell.com; legal questions to legal@mistershell.com.
10. Changes to this policy
We may update this policy from time to time. When we do, we will revise the "Last
updated" date above and the expiry date in security.txt.