Found a crack in the pipes?
Tell us first
If you find a vulnerability in hydrant.dev, the Hydrant app, its API or its MCP endpoint, email security@hydrant.dev. Useful reports include cross-workspace or cross-account access, authentication or agent-credential scope bypasses, exposed data, injection and stored cross-site scripting.
Describe the affected URL or endpoint, the steps to reproduce and the impact you observed. Use accounts and workspaces you own or have permission to use. Keep other people’s data, and any credentials you came across, out of the report.
Out of scope
Denial of service, load or volume testing, and anything that degrades the service for others. Social engineering or phishing of the operator or other users. Physical attacks. Third-party services Hydrant relies on, such as GitHub, Cloudflare, Neon, Stripe, Resend, Sentry, PostHog and Better Stack: report those to the provider. Automated scanner output without a demonstrated impact.
Good-faith research
If you make a good-faith effort to follow this page, we will not pursue legal action against you for that research or treat it as a violation of the Terms. In return: test only against accounts and workspaces you own or have permission to use; access no more of anyone else’s data than the minimum needed to show the problem, then stop and report it; do not degrade the service or work around rate limits; delete any data you obtained; and do not disclose the issue publicly until a fix is released or 90 days after your report, whichever comes first.
This statement does not cover testing of third-party services and is not legal advice.
What happens next
You will get an acknowledgment within 3 business days and a status update within 10 business days. We will coordinate disclosure timing with you. Fix timing depends on severity; there is no promised fix date.
There is no bug bounty or paid reward.
How Hydrant is built
Sign-in uses GitHub, so Hydrant stores no passwords. Agent keys and MCP tokens are stored only as hashes, and provider OAuth tokens are encrypted. Backups are encrypted, with decryption keys held outside the application and its cloud providers. Card details are handled by Stripe and never reach Hydrant. Production access is limited to the operator’s own accounts.