LEGAL / SECURITY
Vulnerability disclosure
Report security issues privately so they can be investigated without exposing users or data.
On this page
OpenDeco-controlled application code and production web properties are in scope. Third-party platform infrastructure belongs to its operator. Contact OpenDeco before active testing that could affect availability, accounts or data.
How to report
Email security@opendeco.net. Include the affected service or code, the impact, precise reproduction steps and whether you want public credit. Do not publish the report or open a public issue before coordination.
Scope
OpenDeco application code and OpenDeco-controlled production hostnames are in scope. Infrastructure operated by a hosting, identity, DNS, source-control or email provider must also be reported to that provider.
Testing boundaries
- Use only accounts and data you own or have explicit permission to test.
- Do not delete, corrupt, overwrite, encrypt or retain data.
- Do not access another person's data, credentials or private research records.
- Do not perform denial-of-service, resource-exhaustion, phishing or social-engineering tests.
- Stop when a finding is proved; do not pivot further into systems or leave persistent access behind.
Sensitive data
If you encounter personal data, restricted research data or a credential, stop testing, describe what was accessed in the private report and delete local copies after the finding is confirmed.
Safe harbour
Launch gate: formal safe-harbour wording requires counsel review. Until approved wording is published, request written authorization before intrusive testing; the private reporting channel remains open for findings discovered through normal use or passive review.
Response process
OpenDeco will assess reproducibility and impact, coordinate remediation and provide factual updates where contact details are available.
| Stage | Target |
|---|---|
| Acknowledgement | 5 working days |
| Initial assessment | 10 working days |
| Update while work continues | Every 14 days |
Coordinated disclosure
Agree a disclosure date with OpenDeco before publication. Reporter credit is optional. OpenDeco does not operate a bug-bounty programme or promise payment for reports.
Security contact file
The machine-readable security contact file carries the reporting address, policy link, preferred language and expiry date.