generated: '2026-09-12' method: searched source: >- https://github.com/appwrite/appwrite/blob/main/SECURITY.md (fetched verbatim 2026-09-12), https://appwrite.io/docs/advanced/security and https://appwrite.io/docs/advanced/security/penetration-tests. provider: Appwrite providerId: appwrite program_published: true program_type: coordinated disclosure bug_bounty: false bug_bounty_note: >- No HackerOne, Bugcrowd or Intigriti program and no published bounty table. Appwrite runs a coordinated-disclosure process with a private reporting channel, not a paid bounty. security_txt: served: false note: >- No /.well-known/security.txt on appwrite.io, www.appwrite.io, cloud.appwrite.io, fra.cloud.appwrite.io or mcp.appwrite.io — all returned 404 on 2026-09-12. The policy exists; it is just not discoverable at the RFC 9116 path. See well-known/appwrite-well-known.yml. channels: - type: private-vulnerability-reporting url: https://github.com/appwrite/appwrite/security/advisories/new preferred: true - type: email contact: security@appwrite.io policy_url: https://github.com/appwrite/appwrite/blob/main/SECURITY.md policy_pointer_in_apis_yml: https://github.com/appwrite/appwrite/blob/main/SECURITY.md public_reporting_prohibited: >- Appwrite explicitly asks reporters NOT to use public GitHub issues, discussions or pull requests. report_contents_requested: - A description of the issue and why it is security-sensitive - Affected versions, tags or commit SHAs - Steps to reproduce, or a proof of concept - Impact (confidentiality, integrity, availability, or privilege) - Any suggested mitigations or fixes process: >- Appwrite acknowledges the report, follows up with next steps, works on a fix if confirmed, and coordinates public disclosure with the reporter, asking for reasonable time before public discussion. scope: covered: The Appwrite server in the appwrite/appwrite repository. other_projects: >- Issues in SDKs, Console or Cloud go to that project's own security policy where one exists, or to security@appwrite.io. supported_versions: >- Security updates are published for the latest stable self-hosted release; support phases and long-term coverage follow https://appwrite.io/docs/apis/release-policy. proactive_testing: penetration_tests: true detail: >- Periodic third-party penetration tests and vulnerability assessments, with an internal and external information-security risk-management process and a risk treatment plan. docs: https://appwrite.io/docs/advanced/security/penetration-tests advisories: https://github.com/appwrite/appwrite/security/advisories maintainers: - FN: Kin Lane email: kin@apievangelist.com