Security Policy
authentik takes security very seriously. We follow the rules of responsible disclosure, and we urge our community to do so as well, instead of reporting vulnerabilities publicly. This allows us to patch the issue quickly, announce it's existence and release the fixed version.
Independent audits and pentests
In May/June of 2023 Cure53 conducted an audit and pentest. The results are published on the Cure53 website. For more details about authentik's response to the findings of the audit refer to 2023-06 Cure53 Code audit.