If you find a security issue in Altera, email [email protected].
What to include
The URL or API endpoint where you found the issue
The steps to reproduce it
The request or payload you used
A screenshot or short recording, if you have one
What is in scope
The Altera app at app.getaltera.com
The Altera API at api.getaltera.com
The Altera MCP server at mcp.getaltera.com
The website at getaltera.com
The
alteraCLI published on npm
What is out of scope
Services Altera uses but does not operate, such as Shopify, Intercom (this help center), Netlify, and Google Cloud. Report those to the provider.
Findings with no practical impact, for example missing headers on static pages, version banners, or automated scanner output without a working proof of concept.
Rewards
Altera does not have a bug bounty program and does not pay for security reports.
