Skip to main content

Reporting a Security Issue

Last Updated: September 16, 2026

If you find a security issue in Altera, email security@getaltera.com.

Include the URL, the steps to reproduce the issue, and the request or payload you used. A screenshot or short recording helps. We read every report.

Scope
#

Reports about these are in scope:

  • The Altera app at app.getaltera.com
  • The Altera API at api.getaltera.com
  • The Altera MCP server at mcp.getaltera.com
  • This website, getaltera.com
  • The altera CLI published on npm

Out of scope
#

  • Services we use but do not operate, such as Shopify, Intercom (support.getaltera.com), Netlify, and Google Cloud. Report those to the provider.
  • Findings with no practical impact, for example missing headers on static pages, version banners, or automated scanner output without a working proof of concept.

Rewards
#

Altera does not have a bug bounty program and does not pay for security reports.

Machine-readable contact
#

The same contact is published at /.well-known/security.txt in the RFC 9116 format, on this site and on app, api, and mcp.getaltera.com.