Last Updated: September 16, 2026
If you find a security issue in Altera, email security@getaltera.com.
Include the URL, the steps to reproduce the issue, and the request or payload you used. A screenshot or short recording helps. We read every report.
Scope#
Reports about these are in scope:
- The Altera app at app.getaltera.com
- The Altera API at api.getaltera.com
- The Altera MCP server at mcp.getaltera.com
- This website, getaltera.com
- The
alteraCLI published on npm
Out of scope#
- Services we use but do not operate, such as Shopify, Intercom (support.getaltera.com), Netlify, and Google Cloud. Report those to the provider.
- Findings with no practical impact, for example missing headers on static pages, version banners, or automated scanner output without a working proof of concept.
Rewards#
Altera does not have a bug bounty program and does not pay for security reports.
Machine-readable contact#
The same contact is published at /.well-known/security.txt in the RFC 9116 format, on this site and on app, api, and mcp.getaltera.com.
