SECURITY
Report a security issue.
If you find a vulnerability in Terrarium or terrarium.watch, send a private report before publishing details.
What to include
- The affected command, page, package version, or desktop build.
- Steps that reproduce the issue with non-sensitive test data.
- The impact you observed and any temporary mitigation.
Send only what the report needs. Do not include live credentials, private repositories, customer data, or complete agent transcripts.
Testing boundaries
Test only systems and data you are authorized to use. Do not disrupt the service, access another person's data, use social engineering, or keep data after the report is complete. Terrarium does not currently offer a paid bug bounty.
Contact
Send the report to hello@terrarium.watch with the subject Terrarium security report. Ordinary product questions belong in support.