mirror of
https://github.com/crewAIInc/crewAI.git
synced 2026-04-30 23:02:50 +00:00
Create a dedicated Security Policy page (docs/{en,pt-BR,ko,ar}/security.mdx)
with vulnerability reporting instructions pointing to the Bugcrowd VDP
(crewai-vdp-ess@submit.bugcrowd.com), consistent with the updated security
policy from PR #5096.
The page is added to the Documentation tab navigation (after Telemetry)
across all versions and languages in docs.json.
This is a top-level security page, not buried inside MCP docs.
23 lines
996 B
Plaintext
23 lines
996 B
Plaintext
---
|
|
title: Security Policy
|
|
description: Learn how to report security vulnerabilities and about CrewAI's security practices.
|
|
icon: shield
|
|
mode: "wide"
|
|
---
|
|
|
|
## Reporting Security Vulnerabilities
|
|
|
|
If you discover a security vulnerability in CrewAI, please report it responsibly through our Bugcrowd Vulnerability Disclosure Program (VDP):
|
|
|
|
**Submit reports to:** [crewai-vdp-ess@submit.bugcrowd.com](mailto:crewai-vdp-ess@submit.bugcrowd.com)
|
|
|
|
<Warning>
|
|
**Do not** disclose vulnerabilities via public GitHub issues, pull requests, or social media. Reports submitted via channels other than Bugcrowd will not be reviewed.
|
|
</Warning>
|
|
|
|
For full details, see our [Security Policy on GitHub](https://github.com/crewAIInc/crewAI/blob/main/.github/security.md).
|
|
|
|
## Security Resources
|
|
|
|
- **[MCP Security Considerations](/mcp/security)** — Best practices for securely integrating MCP servers with your CrewAI agents, including transport security, prompt injection risks, and server implementation advice.
|