generated: '2026-08-13' method: searched source: https://umami.is/security provider: Umami providerId: umami description: >- Umami publishes a responsible vulnerability disclosure policy on its security page, with a dedicated reporting address, a report-quality checklist and rules of engagement for researchers. It is a policy, not a bounty. policy: published: true url: https://umami.is/security section: Responsible vulnerability disclosure contact: security@umami.is contact_kind: email scope: >- Umami and Umami Cloud. Explicitly OUT of scope: customer-controlled self-hosted installations, which must not be tested without the operator's permission. statement: >- "We welcome reports from security researchers and customers who believe they have discovered a vulnerability in Umami or Umami Cloud." response_commitment: >- "We will review good-faith reports and keep the reporter informed as the issue is investigated." No numeric acknowledgement or remediation SLA is published. safe_harbor: not_stated bug_bounty: operates: false statement: >- "Umami does not currently operate a guaranteed paid bug-bounty program." platforms_checked: [HackerOne, Bugcrowd, Intigriti] platforms_found: [] report_should_include: - The affected product, URL, API endpoint, or software version - A description of the vulnerability and its potential impact - Reproduction steps or a proof of concept - Any relevant logs, screenshots, or request details - Preferred contact information rules_of_engagement: - Do not access, modify, download, or delete customer data - Do not disrupt Umami Cloud or degrade service availability - Do not perform denial-of-service, spam, or social-engineering attacks - Do not test against customer-controlled self-hosted installations without permission - Use accounts and data that you own whenever possible - Give Umami a reasonable opportunity to investigate and remediate before public disclosure advisories: channel: GitHub Security Advisories url: https://github.com/umami-software/umami/security/advisories note: >- The security page states Umami investigates "reported vulnerabilities and GitHub security advisories" as part of its SDLC. Because Umami is open source under MIT, GitHub advisories are the practical disclosure channel for the self-hosted product. gaps: - >- No /.well-known/security.txt on any Umami host (umami.is, api.umami.is, cloud.umami.is, docs.umami.is all miss — see well-known/umami-well-known.yml). The policy exists and the contact exists; only the RFC 9116 machine-readable form is missing. This is the cheapest available fix on this artifact. - No published acknowledgement or remediation timeline. - No safe-harbor language. evidence: - url: https://umami.is/security status: 200 - url: https://umami.is/.well-known/security.txt status: 404 - url: https://api.umami.is/.well-known/security.txt status: 405 maintainers: - FN: Kin Lane email: kin@apievangelist.com