generated: '2026-08-27' method: searched source: https://github.com/karrioapi/karrio/blob/HEAD/SECURITY.md provider: Karrio providerId: karrio description: >- Karrio publishes a vulnerability disclosure policy, but only in the place an open-source contributor looks — SECURITY.md in the monorepo. Nothing on karrio.io or in the docs points to it, and no /.well-known/security.txt is served on any host, so a security researcher arriving at the website has no published route to report. program: published: true type: email-disclosure policy_url: https://github.com/karrioapi/karrio/blob/HEAD/SECURITY.md contact: hello@karrio.io contact_type: email quoted: >- "Please report security vulnerabilities to hello@karrio.io." bug_bounty: false platform: null safe_harbor_stated: false response_sla_stated: false disclosure_timeline_stated: false pgp_key: null supported_versions: policy: latest-only quoted: >- "We always recommend using the latest version of Karrio to ensure you get all security updates." note: >- No LTS branch and no backport policy. On a self-hosted platform this puts the burden of staying patched entirely on the operator, and the 2026.1.32 changelog is explicit that recent releases fixed production-affecting security issues (an MD5 PASSWORD_HASHERS override reaching production, and a migration that could cascade into shipment history). gaps: - No /.well-known/security.txt on karrio.io, docs.karrio.io or app.karrio.io (all 404 or 503, probed 2026-08-27). - No security or trust page on karrio.io (https://karrio.io/security returns 404). - No named certification (SOC 2, ISO 27001, PCI, HIPAA) is published anywhere, though karrio.io/platform markets "enterprise-grade security with advanced compliance controls" and "carrier, data and security compliance". maintainers: - FN: Kin Lane email: kin@apievangelist.com