Upstash Vulnerability Disclosure Policy
Reporting a vulnerability
If you believe you've found a security vulnerability in Upstash, please tell us. Email security@upstash.com with:
- What the vulnerability is and where it is (the URL, API, product or repository)
- Steps to reproduce it, with a proof of concept if you have one
- What an attacker could do with it
- How to reach you, and whether you'd like to be credited
Please report privately and don't share details publicly until we've fixed the issue.
What to expect
- We acknowledge your report within 3 business days.
- We investigate, confirm whether it's a vulnerability, and keep you posted as we work on a fix.
- We tell you when it's fixed, and credit you if you'd like to be.
Scope
- upstash.com and its subdomains, including the Upstash Console
- Upstash services and their APIs: Redis, Vector, Search, QStash, Workflow, Box and Blob
- Upstash's open-source SDKs and tools at github.com/upstash
- Context7, including its MCP server and API
- Upsy
Out of scope
- Denial of service, load or stress testing
- Social engineering, phishing, or physical attacks against Upstash, its employees or customers
- Spam, or reports from automated scanners without a demonstrated impact
- Missing security headers, cookie flags or best practices without a demonstrated impact
- Vulnerabilities in third-party services we use, which should be reported to their owners
Guidelines
When researching, please:
- Only use accounts and data you own. Don't access, change or delete other people's data.
- Stop and report as soon as you reach data that isn't yours, and don't keep or share it.
- Don't degrade the service for others: no denial of service, spam or automated scanning at high volume.
- Only do what's needed to demonstrate the vulnerability.
Safe harbor
We won't take legal action against you, or ask others to, for security research carried out in good faith and within this policy. If you're unsure whether something is allowed, ask us at security@upstash.com before you do it.
Bug bounty
We pay rewards for critical vulnerabilities:
- Accessing another customer's data or account (reading or changing their data, messages, files, keys or settings)
- Bypassing authentication, or taking over an account
- Running code on Upstash's infrastructure
- Leaked secrets that allow any of the above
Show access across customers between two accounts you own. Accessing real customers' data isn't allowed and makes a report ineligible.
Rewards depend on impact and are paid for the first valid report of an issue we fix. Upstash decides whether a report qualifies and the amount. Employees and contractors of Upstash aren't eligible, nor are people we can't legally pay.
Other valid reports are welcome too: we credit them, but don't pay a reward.