Skip to main content
EVOKORE// SKILLS / SECURITY
deepset-ai/haystacksecuritysha 339EDD823E62

SECURITY

security policy

Security Policy

Reporting a Vulnerability

The deepset team takes the security of Haystack seriously. We appreciate your efforts to responsibly disclose security vulnerabilities.

How to Report

  • Email: security@deepset.ai
  • Do NOT create public GitHub issues for security vulnerabilities
  • Include as much detail as possible about the vulnerability

Response Timeline

  • Acknowledgment: Within 48 hours of report
  • Assessment: Within 5 business days
  • Fix: Targeted within 30 days for critical issues
  • Disclosure: Coordinated with reporter after fix is released

Supported Versions

VersionSupported
2.xYes
1.xCritical security fixes only
< 1.0No

Security Best Practices for Haystack Users

API Key Management

  • Store API keys in environment variables, never in code
  • Use .env files for local development (add to .gitignore)
  • Rotate API keys regularly
  • Use scoped API keys with minimum required permissions

Document Store Security

  • Enable authentication on all document store backends
  • Use TLS for connections to external document stores
  • Restrict network access to document stores
  • Regular security updates for all storage backends

Pipeline Security

  • Validate and sanitize all user inputs before pipeline execution
  • Use content filtering components for user-facing applications
  • Monitor pipeline execution logs for anomalous patterns
  • Implement rate limiting for public-facing pipeline endpoints

Deployment

  • Run Haystack applications in isolated environments
  • Use container security scanning for Docker deployments
  • Keep all dependencies up to date
  • Enable audit logging for production deployments

Security Advisories

Security advisories are published via GitHub Security Advisories and announced on our community channels.