Support and security
Bugs go in the open. Vulnerabilities do not — not at first.
Reporting a bug
The tracker is public and you do not need an account with us to use it. That is deliberate: a bug that is only visible to the vendor is a bug other customers cannot know about.
What helps:
- the operator version and the Kubernetes version,
- what you expected and what happened,
- the relevant log lines, redacted.
Please keep cluster names, image references, policy contents, credentials and tokens out of a public issue.
Disclosing a vulnerability
Do not open an issue. Use the process on attestkeep.com/security, which gives you an address and a key.
What you can expect: an acknowledgement that a person has read it, an assessment, and a fix with credit if you want it. What we ask: time to ship the fix before it is public.
Support by plan
| Plan | Support |
|---|---|
| Community | Public issue tracker |
| Team | |
| Business | E-mail, prioritised |
| Enterprise | Terms set in the agreement |
Community has no paid support and that is not a trap: every capability is on, the tracker is public, and this documentation is not held back from the edition most likely to need it.
Getting in touch
support@attestkeep.com for anything that is not a bug report — pricing, procurement paperwork, an Enterprise agreement, or a question this documentation failed to answer. The last one is also worth telling us about, because it is a documentation bug.