Report a vulnerability
We take security seriously and welcome reports from the community. If you've found a vulnerability in Canopy, please tell us before disclosing it publicly.
How to report
Email security@8starlabs.com with:
- A description of the issue and its potential impact.
- Steps to reproduce (a proof-of-concept helps).
- The affected URL, endpoint, or area of the product.
If you'd rather not email, use support and mark it as a security report.
Please practice responsible disclosure
Give us a reasonable window to investigate and ship a fix before sharing details publicly. We'll keep you updated on our progress.
Our commitment
- We'll acknowledge your report promptly and keep you informed as we work.
- We won't pursue legal action against good-faith research that respects user privacy, avoids data destruction, and doesn't degrade the service.
- We're happy to credit you once a fix has shipped, if you'd like.
Please avoid
- Accessing, modifying, or deleting data that isn't yours.
- Running automated scans that degrade the service for others.
- Social engineering, phishing, or physical attacks against our team or users.
Thank you for helping keep Canopy and its users safe.