// security
Security
Last updated October 2026
kubelatch stands between people and their clusters, so a bug in it is usually a security bug. If you find one, tell us first; we will fix it and say so in public, with credit to you.
Report a vulnerability
Write to security@kubelatch.com, and not to a public issue or discussion. Include:
- the version of kubelatch, or the address of the site, affected;
- what the vulnerability is and what an attacker could do with it;
- the steps to reproduce it, and a proof of concept if you have one;
- how you would like to be credited, if at all.
Send no real personal data or credentials of anyone else. If you need an encrypted channel, say so in your first e-mail and we will agree on one.
What happens next
- We acknowledge your report within 3 business days.
- We confirm the problem, tell you how serious we think it is, and keep you informed while we fix it.
- The fix ships in a new release, with a note in its release notes, and we credit you there if you want.
- We ask you to keep the details private until the fix is released or 90 days have passed since your report, whichever comes first. If we need more time, we will tell you why and agree on a date with you.
There is no paid bug bounty today.
Research in good faith
We will not take legal action against research that follows this policy: tests within the scope below, no access to or change of other people’s data beyond what proves the problem, no degradation of any service, and a prompt report to us. If in doubt about whether something is in scope, ask us first.
Scope
- The kubelatch software: the server, the command-line client, the container image, the Helm chart and the plugins.
- kubelatch.com, docs.kubelatch.com and licensing.kubelatch.com.
Out of scope:
- denial of service and load tests;
- social engineering, phishing or physical attacks against people at Picaporte Labs or our customers;
- the kubelatch instances of our customers: test your own installation. A vulnerability of the software that you find on your own instance is in scope.
How kubelatch is built for security
The security model in the documentation says what kubelatch guarantees, what it does not, and what each guarantee rests on. In short:
- One impersonating proxy: people, CI and AI agents reach the clusters through kubelatch each with its own credential, which expires and can be revoked at once, and the cluster sees the real person.
- Every request is audited, with a row written before it reaches the cluster.
- The license key is verified offline, and kubelatch calls no service of Picaporte Labs: there is no telemetry.
- The image is distroless and runs as a non-root user, with no shell and nothing but the binary.
External review
A prospective or existing customer can review the source code under a non-disclosure agreement; write to pro@kubelatch.com. An external penetration test is planned, and its summary will be published on this page.
Supported versions
Security fixes ship in the latest release of kubelatch, and only the latest release is supported. Keep your installation up to date.