Skip to main content

How to Report a Security Issue

Where to send security reports about Altera, what to include, and what is in scope

If you find a security issue in Altera, email [email protected].

What to include

  • The URL or API endpoint where you found the issue

  • The steps to reproduce it

  • The request or payload you used

  • A screenshot or short recording, if you have one

What is in scope

  • The Altera app at app.getaltera.com

  • The Altera API at api.getaltera.com

  • The Altera MCP server at mcp.getaltera.com

  • The website at getaltera.com

  • The altera CLI published on npm

What is out of scope

  • Services Altera uses but does not operate, such as Shopify, Intercom (this help center), Netlify, and Google Cloud. Report those to the provider.

  • Findings with no practical impact, for example missing headers on static pages, version banners, or automated scanner output without a working proof of concept.

Rewards

Altera does not have a bug bounty program and does not pay for security reports.

See also

Did this answer your question?