Security Policy
Supported Versions
| Version | Supported |
|---|---|
| 3.x | Yes |
| 2.x | Security patches only |
| < 2.0 | No |
Reporting a Vulnerability
We take security vulnerabilities seriously. If you discover a security issue in Conductor, please report it responsibly.
How to Report
- Do NOT open a public GitHub issue for security vulnerabilities
- Email security@conductor-oss.org with details of the vulnerability
- Include steps to reproduce the issue if possible
- Allow up to 72 hours for an initial response
What to Include
- Description of the vulnerability
- Steps to reproduce
- Potential impact assessment
- Suggested fix (if any)
Security Practices
Authentication and Authorization
- Conductor Server supports pluggable authentication providers
- Role-based access control (RBAC) for workflow and task management
- API token-based authentication for task workers
- OAuth 2.0 integration for enterprise deployments
Data Protection
- All inter-service communication supports TLS encryption
- Workflow input/output data can be encrypted at rest
- Sensitive task parameters support field-level encryption
- Audit logging for all administrative actions
Task Worker Security
- Task workers authenticate using API tokens with configurable scopes
- Worker-to-server communication is encrypted in transit
- Task execution is isolated per worker instance
- No arbitrary code execution in the orchestration layer
Disclosure Timeline
- Day 0: Vulnerability reported
- Day 1-3: Initial acknowledgment and triage
- Day 7-14: Fix developed and tested
- Day 14-30: Coordinated public disclosure