generated: '2026-09-06' method: searched source: https://github.com/langgenius/dify/blob/main/SECURITY.md description: >- Dify publishes a written security policy in the root of its main open-source repository. Intake is GitHub Security Advisories — private, coordinated, and maintainer-reviewed. There is no /.well-known/security.txt on any Dify host and no bug-bounty program. policy_url: https://github.com/langgenius/dify/blob/main/SECURITY.md raw_url: https://raw.githubusercontent.com/langgenius/dify/main/SECURITY.md http_status: 200 intake: channel: GitHub Security Advisories url: https://github.com/langgenius/dify/security/advisories/new private: true public_issues_prohibited: true requested_report_contents: - A description of the vulnerability - Steps to reproduce, if safe to share privately - Affected components, versions, or configurations - Potential impact - Any suggested mitigation or fix, if available coordinated_disclosure: true coordinated_disclosure_note: >- The policy asks reporters to avoid publicly disclosing details until a report has been reviewed and, where appropriate, a fix is available. Maintainers coordinate follow-up in the advisory. bug_bounty: present: false note: Checked HackerOne, Bugcrowd and Intigriti naming; no Dify program found and none is advertised. security_txt: present: false note: >- /.well-known/security.txt returns 404 on dify.ai, www.dify.ai, api.dify.ai, docs.dify.ai and cloud.dify.ai. See well-known/dify-well-known.yml. security_contact_alternate: note: >- The Vanta-hosted trust center at https://security.dify.ai/ invites paid-plan customers to request the SOC 2 Type 1 and penetration-test reports by security email. trust_center: security/dify-trust-center.yml