Legal
Security
Last updated August 31, 2026
01Reporting a vulnerability
If you find a security issue in Astrea, please report it privately so we can fix it before it is made public.
Write to security@getastrea.com with:
- a description of the issue and its potential impact;
- the affected component (website, desktop application, gateway/backend, or Discord bot) and version, if known; and
- clear reproduction steps or a proof of concept.
Please do not include sensitive customer data (real account credentials, other users' personal information, payment details, etc.) in your report; a redacted example or your own test account is sufficient.
We treat every report as confidential. We will acknowledge receipt within 2 business days, and keep you informed as we investigate and work on a fix. Please give us a reasonable opportunity to address an issue before disclosing it publicly, and avoid actions that could degrade the Service or affect other users while testing.
02Safe Harbor
We consider security research conducted in good faith, consistent with this policy, to be authorized. We will not pursue legal action against researchers who:
- make a genuine, good-faith effort to avoid privacy violations, data destruction, and service disruption;
- report a vulnerability promptly and do not exploit it beyond what is necessary to demonstrate it; and
- do not access, modify, or retain data belonging to other users.
If a third party initiates legal action related to research conducted under this policy, we will make it known that your actions were authorized.
03What is in scope
- The Astrea website (getastrea.com and api.getastrea.com).
- The Astrea gateway and backend (accounts, billing, model gateway, admin control plane, update feed).
- The Astrea desktop application (IDE client).
- The Discord support bot.
- Anything documented in our public repositories.
04What is out of scope
- Third-party services we integrate with, including model providers (OpenRouter, opencode, Groq, etc.) and our payment processor (Stripe); please report issues in those services directly to their operators.
- Issues that require social engineering of our staff or users, or physical access to a device you own.
- Self-inflicted issues, such as those arising from a jailbroken or otherwise compromised device, or a misconfigured local environment.
- Known limitations and issues already documented in our public repositories or previously reported to us.
- Denial-of-service attacks, automated vulnerability scanning that generates significant traffic, and spam or social-engineering attacks against our support channels.
- Reports based solely on missing security headers, best-practice deviations, or automated scanner output without a demonstrated, exploitable impact.
05Our security practices
- Local-first by design. Your source code, credentials, and project history stay on your machine and are never uploaded to our servers; see our Privacy Policy (https://getastrea.com/privacy) for details.
- Credential isolation. Provider API keys and account secrets live only on backend servers, in environment variables, and are never exposed to the browser or bundled into the desktop application.
- Encryption in transit. All traffic between the desktop application, the website, and the gateway is encrypted using TLS.
- Least-privilege access. Access to production infrastructure is limited to authorized personnel, requires strong authentication, and is logged and audited.
- Payment isolation. Card details are handled directly by Stripe; we never receive or store full card numbers.
- Dependency and update hygiene. The desktop application checks for updates through a signed update feed so you can stay on a patched version.
06Disclosure process
When we confirm a report, we aim to develop and ship a fix before any public disclosure. Typical timeline:
- Acknowledgment: within 2 business days of your report.
- Triage and validation: we confirm the issue, assess severity, and follow up with any questions.
- Remediation: we develop, test, and release a fix. Timeframes vary with severity and complexity; we'll keep you updated.
- Disclosure: once a fix is released, we're happy to coordinate on public disclosure timing and credit.
We will credit reporters who wish to be credited for a valid, responsibly disclosed report, unless you prefer to remain anonymous.
07Bounty
We do not currently operate a paid bug bounty program. We are nonetheless genuinely grateful for responsible reports, and we credit researchers (with permission) in our release notes or a security acknowledgments page.
08Contact
security@getastrea.com
For account-specific privacy requests, see our Privacy Policy (https://getastrea.com/privacy) or contact privacy@getastrea.com instead.
