Aklivity · Vulnerability Disclosure

Aklivity Vulnerability Disclosure

Vulnerability disclosure

Aklivity runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

AI GatewayAPI GatewayAgent InfrastructureApache KafkaAsyncAPIEvent-DrivenIoTKafka ProxyMCPMulti-ProtocolOpen-SourceReal-Time
Program: Hackerone

Disclosure Policy

Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy
Policy

Security Contact

Contact
emailsecurity@aklivity.io
Contact
pgp_keyhttps://drive.google.com/file/d/1f6zCE05h2S2GLRKtkwHuKXAcad-JDUY4/view?usp=sharing
Contact
pgp_noteThe policy says the PGP key is "available at https://aklivity.io/security"; the link on that page resolves to a Google Drive file rather than to a key served from an aklivity.io path.

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-30'
method: searched
source: https://www.aklivity.io/security
program: coordinated-vulnerability-disclosure
bug_bounty: false
bug_bounty_note: >-
  No HackerOne, Bugcrowd or Intigriti program. Disclosure is direct to
  security@aklivity.io under a published Coordinated Vulnerability Disclosure
  Policy.
contact:
  email: security@aklivity.io
  pgp_key: https://drive.google.com/file/d/1f6zCE05h2S2GLRKtkwHuKXAcad-JDUY4/view?usp=sharing
  pgp_note: >-
    The policy says the PGP key is "available at https://aklivity.io/security";
    the link on that page resolves to a Google Drive file rather than to a
    key served from an aklivity.io path.
policy:
  title: Aklivity Coordinated Vulnerability Disclosure Policy
  version: '1.0'
  effective_date: '2025-01-06'
  url: https://cdn.prod.website-files.com/60e49b51af3305d435c286ab/67f984003289ac6baceea454_Aklivity_Vulnerability_Disclosure_Policy.pdf
  format: pdf
  http_status: 200
  scope:
    - source-available and commercial software (Zilla, Zilla Plus)
    - Docker containers and artifacts published by Aklivity
    - documentation, configuration templates and sample deployments
    - publicly accessible domains under aklivity.io
  out_of_scope:
    - third-party dependencies not maintained by Aklivity
    - self-hosted deployments that are fully customer-controlled
  commitments:
    acknowledgment: within 3 business days
    triage: validate the report and assess impact
    coordination: coordinate a remediation timeline and credit the reporter with permission
    disclosure_target: within 90 days of initial report unless otherwise agreed
  researcher_guidelines:
    - do not exploit beyond what is necessary to demonstrate the issue
    - do not access, modify or delete customer or system data
    - do not perform denial-of-service attacks or impact availability
    - allow Aklivity adequate time to investigate before public disclosure
repository_policy:
  url: https://github.com/aklivity/zilla/blob/develop/SECURITY.md
  note: >-
    A SECURITY.md is committed to the zilla repository. Its raw fetch returned
    HTTP 429 (GitHub HTML rate limit) during this pass and was not re-attempted;
    the file's presence is confirmed from the repository tree.
security_txt:
  served: false
  note: >-
    No RFC 9116 /.well-known/security.txt on www.aklivity.io, aklivity.io or
    docs.aklivity.io — all three return 404. A one-line security.txt pointing at
    this policy would be the cheapest fix available to this provider.
  probes:
    - url: https://www.aklivity.io/.well-known/security.txt
      status: 404
    - url: https://aklivity.io/.well-known/security.txt
      status: 404
    - url: https://docs.aklivity.io/.well-known/security.txt
      status: 404
related_documents:
  - title: Aklivity Technical and Organizational Measures (TOMs)
    version: '1.0'
    effective_date: '2025-01-06'
    url: https://cdn.prod.website-files.com/60e49b51af3305d435c286ab/67f98405cd38fed455d270cb_Aklivity_TOMs_Document.pdf
    http_status: 200
    highlights:
      - SAST and dependency scanning in CI/CD; mandatory peer review
      - container images built from minimal hardened bases, scanned with Trivy/Snyk
      - dependencies pinned and verified; SBOM generated and published with each release
      - MFA and RBAC on code repositories, build systems and cloud infrastructure
      - formalized incident response plan for internal systems and supply-chain threats
      - annual security training; secure coding workshops for engineering
    certification_status: >-
      "SOC 2-aligned internal controls (in-progress)". No attested certification
      is published — no SOC 2 report, ISO 27001, PCI, HIPAA or FedRAMP.
    material_fact: >-
      The document states Aklivity "provides a self-managed, container-based
      software solution that customers deploy within their own environments"
      and "does not operate or access customer data or infrastructure by
      default" — the reason this provider has no hosted API surface to secure.
evidence:
  - source: https://www.aklivity.io/security
    kind: disclosure page
    status: 200
    keywords:
      - vulnerability
      - 'security@'
      - coordinated disclosure
      - PGP

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/aklivity-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.