Skip to content

Pre-release. v0.1 is not out yet, so there is nothing to install and no public source to clone — the quickstart builds from a checkout.

Reporting a vulnerability

Email support@subactid.com. Do not open a public issue.

Include:

  • The affected version or commit.
  • A description of the issue.
  • Reproduction steps, if you have them.
  • Acknowledgement within 3 working days.
  • An assessment and a planned fix timeline within 10 working days.
  • Coordinated disclosure. We ask for 90 days before public disclosure, and usually publish sooner once a fix is released.

In scope: the control plane, token issuance and validation, the audit ledger, and the SDKs.

Out of scope:

  • Findings that require an already compromised host.
  • Issues in the quickstart’s Docker Compose configuration, which is a demonstration and is not hardened for production.
  • Denial of service through unbounded request volume.

The threat model lists what Subact ID does and does not defend against.

During 0.x, only the latest release receives security fixes.

Subact ID Pre-release. v0.1 is not out yet.

© 2026 Nikola Živković PR Agencija za programerske usluge Novi Sad. Subact ID is its product.

LegalTermsPrivacy