Graphite · Vulnerability Disclosure

Graphite Com Vulnerability Disclosure

Vulnerability disclosure

Graphite runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

Code ReviewStacked PRsMerge QueueAI Code ReviewDeveloper ToolsGitHub
Program: Hackerone

Disclosure Policy

Policy
Policy

Security Contact

Contact
security@graphite.com

Source

Vulnerability Disclosure

Raw ↑
generated: '2026-08-04'
method: searched
probe: true
probe_result: >-
  probe-security-programs.py returned vdp=none — Graphite serves no
  /.well-known/security.txt (404 on graphite.com and api.graphite.dev, probed
  2026-08-04) and has no /security, /trust or /responsible-disclosure page.
  What follows was found by reading the published documentation instead.
policy:
- https://graphite.com/docs/privacy-and-security
- https://trust.cursor.com
contact:
- security@graphite.com
security_txt:
  present: false
  probed:
  - {url: 'https://graphite.com/.well-known/security.txt', http_status: 404}
  - {url: 'https://graphite.com/security.txt', http_status: 404}
  - {url: 'https://api.graphite.dev/.well-known/security.txt', http_status: 404}
bug_bounty:
  present: false
  platforms: []
  note: >-
    No HackerOne, Bugcrowd, or Intigriti program was found for graphite.com. The
    trust center is operated by the parent company (trust.cursor.com); any bounty
    program would live there and could not be confirmed anonymously — the page is
    a JavaScript application that serves only a title to an unauthenticated
    fetch.
security_practices:
  soc2_type_ii: true
  continuous_penetration_testing: true
  encryption_in_transit: true
  encryption_at_rest: true
  token_encryption: aes-256-cbc with a secret held in AWS Secrets Manager
  layered_key_separation: >-
    Database contents are additionally encrypted with a key stored in a separate
    service, so a database compromise alone does not yield GitHub API tokens.
  ai_data_handling: >-
    AI features are opt-in and do not store or train on customer data; AI
    Summarize is PR-by-PR opt-in and runs on Anthropic's API under terms that
    exclude customer source code from training sets.
  code_indexing: >-
    Opt-in, time-limited code indexing service; documented separately at
    /docs/code-indexing-security.
  source: https://graphite.com/docs/privacy-and-security
evidence:
- source: https://graphite.com/docs/privacy-and-security
  kind: documentation
  quote: >-
    "If you have more questions about this feature, don't hesitate to shoot us a
    message on Slack or email security@graphite.com."
- source: https://graphite.com/docs/privacy-and-security
  kind: documentation
  quote: >-
    "We are SOC 2 Type II compliant... We also continuously pen test."
gaps:
- No RFC 9116 /.well-known/security.txt published on any Graphite host.
- No dedicated responsible-disclosure or vulnerability-reporting page.
- No stated response-time or safe-harbour commitment for reporters.
x-evidence:
  fetched: '2026-08-04'
  urls:
  - {url: 'https://graphite-58cc94ce.mintlify.dev/docs/privacy-and-security.md', http_status: 200}
  - {url: 'https://trust.cursor.com', http_status: 200, content_type: text/html}