The latest published 0.x release is supported. Once 1.0.0 ships, the current
major line is supported.
DO NOT open a public GitHub issue for security vulnerabilities.
Please report security vulnerabilities via one of the following channels:
- Email: security@elnora.ai
- GitHub Security Advisories: Report a vulnerability
Include as much detail as possible:
- Description of the vulnerability
- Steps to reproduce
- Potential impact
- Suggested fix (if any)
- Acknowledgement: Within 48 hours of report
- Initial assessment: Within 5 business days
- Fix and disclosure: Within 90 days of report
We follow a 90-day disclosure timeline. We ask that you:
- Allow us reasonable time to fix the issue before public disclosure
- Do not access or modify other users' data
- Do not perform actions that could negatively impact other users
- Act in good faith to avoid privacy violations, data destruction, and service disruption
In scope:
- The
elnora-vantaCLI and plugin code in this repository - Credential handling: env-var resolution,
~/.config/elnora-vanta/.envstorage (or$VANTA_CONFIG_DIR/.env), the token cache at~/.config/elnora-vanta/token.json, and secret redaction in output and logs - The write-safety gate (anything that lets a write execute without
--confirm, or a destructive operation without--force) - The SSRF regional-host allow-list (
api.vanta.com,api.eu.vanta.com,api.aus.vanta.com) - The publication guard (
scripts/check-no-populated-references.mjs)
Out of scope:
- The Vanta API and platform themselves (report to Vanta)
- Third-party dependencies (please report to their respective maintainers)
- The scopes a user grants their own Vanta OAuth client — those are the user's choice
- Social engineering attacks against Elnora staff
- Denial of service attacks
- Issues in services not operated by Elnora
- Never commit credentials to version control — keep
VANTA_CLIENT_ID/VANTA_CLIENT_SECRETin~/.config/elnora-vanta/.env(or your environment). - Grant the OAuth client only
vanta-api.all:readunless you actually intend to use the write operations. On a read-only credential every write fails at Vanta, so the CLI's--confirm/--forceflags stop being the only safeguard. - Rotate the client secret periodically, and revoke immediately if it is exposed.
- The token cache (
~/.config/elnora-vanta/token.json) is written with mode0600; delete it after revoking a client. - Keep the generated
vanta-*.mdreference cache out of version control — it contains your org's live compliance posture and is gitignored by default.