Websites and Services
Report to: [email protected]
Domains (and subdomains):
- cloudsecurityalliance.org
- csachapter.io
- star.watch
- webfinger.io
CSA also operates many other domains (e.g., event sites, redirects, and aliases). These are hosted on third-party platforms — please report any vulnerabilities in those services directly to the respective platform provider.
Software
Report via: GitHub Private Vulnerability Reporting
- https://github.com/CloudSecurityAlliance/
- https://github.com/CloudSecurityAlliance-Chatbots
- https://github.com/CloudSecurityAlliance-DataSets
- https://github.com/modelcontextprotocol-security/
- https://github.com/RiskRubric/
Report vulnerabilities through the Security tab of the affected repository. See https://github.com/CloudSecurityAlliance/csa-product-security for full details on CSA's product security program.
AI Prompts and Instructions
CSA publishes AI prompts, skills, system instructions, and related artifacts. If you find a security vulnerability in a CSA-published AI artifact:
- If the artifact is in a GitHub repository, report it through the Security tab of that repository.
- If the artifact is published on a CSA website, report to: [email protected]
Security vulnerabilities in AI artifacts include issues such as prompt injection that bypasses an intended security control, unauthorized tool execution, authentication or authorization bypass, and data exfiltration. General model behavioral observations without a specific security impact are not in scope.
What is not in scope:
- cloudsecurityalliance.auth0.com/* (please file an issue with Auth0 at https://auth0.com/responsible-disclosure-policy)
- Any "best practices" for SPF/DKIM/DMARC/BIMI/TLS/HTTP HEADERS
- Any wordpress.com related items like "disabling xmlrpc.php"
Bug Bounty:
We are a non-profit organization and do not provide monetary rewards for vulnerability reports.
Acknowledgements:
We do not maintain a separate acknowledgements page. For GitHub repositories, reporters are automatically credited on published security advisories.