---
title: Vulnerability Management
description: Langfuse vulnerability management program and practices.
---

# Vulnerability Management

Langfuse is committed to maintaining the security of its systems and protecting customer data. Our vulnerability management program is a key component of this commitment, designed to identify, assess, prioritize, and remediate security vulnerabilities in a timely manner.

## Identification

We employ a multi-layered approach to identify potential vulnerabilities:

- **Automated Scanning:** We utilize industry-standard tools, including **GitHub code scanning** and **Snyk**, to continuously scan our codebase, dependencies, and infrastructure for known vulnerabilities.
- **External Penetration Testing:** Langfuse undergoes regular [penetration tests](/security/penetration-testing) conducted by independent third-party security experts. Findings from these tests are integrated into our remediation process.
- **Responsible Disclosure Program:** We encourage security researchers to report potential vulnerabilities through our [responsible disclosure program](/security/responsible-disclosure), which routes submissions through Bugcrowd.
- **Internal Reviews:** Our engineering teams conduct regular security reviews of code and infrastructure configurations.

## Triage and Remediation

Identified vulnerabilities are triaged based on severity and potential impact. High-priority vulnerabilities are addressed promptly according to predefined Service Level Agreements (SLAs). Our remediation process involves:

1.  **Assessment:** Understanding the vulnerability's impact and exploitability.
2.  **Prioritization:** Ranking vulnerabilities based on risk.
3.  **Remediation:** Applying patches, configuration changes, or code fixes.
4.  **Verification:** Confirming the vulnerability has been successfully addressed.

## Compliance

Our vulnerability management processes are designed to meet the requirements of our [**SOC 2 Type II**](/security/soc2) and [**ISO 27001**](/security/iso27001) certifications. This includes maintaining a formal Vulnerability Management Policy, regular scanning, timely remediation, and detailed record-keeping.

<!-- agent-instructions -->

---

## Agent Instructions

This page is part of the [Langfuse](https://langfuse.com) documentation, published as plain Markdown for AI agents. Every page is available as Markdown by appending `.md` to its URL, or by sending an `Accept: text/markdown` header. This page: `https://langfuse.com/security/vulnerability-management.md`.

### Querying these docs

If the answer is not on this page, query the documentation instead of guessing:

- **Semantic search** across all Langfuse docs, returning an answer with the relevant pages and excerpts. Ask a specific, self-contained question:

  ```bash
  curl -sG "https://langfuse.com/api/search-docs" --data-urlencode "query=How do I trace a LangGraph agent?"
  ```

- **Index of every page**: <https://langfuse.com/llms.txt>, with per-section indexes [llms-docs.txt](https://langfuse.com/llms-docs.txt), [llms-integrations.txt](https://langfuse.com/llms-integrations.txt), and [llms-self-hosting.txt](https://langfuse.com/llms-self-hosting.txt).

### Before writing Langfuse code

- **Install the [Langfuse Agent Skill](https://langfuse.com/docs/api-and-data-platform/features/agent-skill).** It encodes Langfuse's own best practices for instrumentation, prompt management, and evaluation, and materially improves results.
- **Read [What does a good trace look like?](https://langfuse.com/docs/observability/best-practices.md)** before instrumenting an application.
- **Verify endpoints, parameters, and response fields** against the [API reference](https://api.reference.langfuse.com) instead of inferring them from code examples.
- **Use the [Langfuse CLI](https://langfuse.com/docs/api-and-data-platform/features/cli)** (`npx langfuse-cli api <resource> <action>`) to read or write traces, prompts, datasets, and scores from the terminal.

Found an error in these docs? Please open an issue at <https://github.com/langfuse/langfuse-docs/issues>.
