---
title: Reporting a Security Issue
date: 2026-09-16
description: How to report a security issue in Altera, what is in scope, and where the security contact is published.
url: https://www.getaltera.com/security/
---
**Last Updated:** September 16, 2026

If you find a security issue in Altera, email [security@getaltera.com](mailto:security@getaltera.com).

Include the URL, the steps to reproduce the issue, and the request or payload you used. A screenshot or short recording helps. We read every report.

## Scope

Reports about these are in scope:

- The Altera app at app.getaltera.com
- The Altera API at api.getaltera.com
- The Altera MCP server at mcp.getaltera.com
- This website, getaltera.com
- The `altera` CLI published on npm

## Out of scope

- Services we use but do not operate, such as Shopify, Intercom (support.getaltera.com), Netlify, and Google Cloud. Report those to the provider.
- Findings with no practical impact, for example missing headers on static pages, version banners, or automated scanner output without a working proof of concept.

## Rewards

Altera does not have a bug bounty program and does not pay for security reports.

## Machine-readable contact

The same contact is published at [/.well-known/security.txt](/.well-known/security.txt) in the [RFC 9116](https://www.rfc-editor.org/rfc/rfc9116) format, on this site and on app, api, and mcp.getaltera.com.

