Pre-release. v0.1 is not out yet, so there is nothing to install and no public source to clone — the quickstart builds from a checkout.
Reporting a vulnerability
How to report
Section titled “How to report”Email support@subactid.com. Do not open a public issue.
Include:
- The affected version or commit.
- A description of the issue.
- Reproduction steps, if you have them.
What to expect
Section titled “What to expect”- Acknowledgement within 3 working days.
- An assessment and a planned fix timeline within 10 working days.
- Coordinated disclosure. We ask for 90 days before public disclosure, and usually publish sooner once a fix is released.
In scope: the control plane, token issuance and validation, the audit ledger, and the SDKs.
Out of scope:
- Findings that require an already compromised host.
- Issues in the quickstart’s Docker Compose configuration, which is a demonstration and is not hardened for production.
- Denial of service through unbounded request volume.
The threat model lists what Subact ID does and does not defend against.
Supported versions
Section titled “Supported versions”During 0.x, only the latest release receives security fixes.
Subact ID
Pre-release. v0.1 is not out yet.
© 2026 Nikola Živković PR Agencija za programerske usluge Novi Sad. Subact ID is its product.