Policy

Reporting security issues

Effective 3 October 2026

§ 1

How to report

If you think you’ve found a security vulnerability in anything Ornis Labs runs, please email security@ornislabs.com. Please include:

  • what you found and where (the address or system affected),
  • steps to reproduce it,
  • the impact you think it has,
  • how you’d like to be credited, if at all.
§ 2

What we’ll do

  • Confirm we received your report within 5 business days.
  • Keep you updated while we investigate and fix it.
  • Credit you publicly once it’s fixed, if you’d like.

We don’t currently run a paid bug bounty.

§ 3

Safe harbour

If you act in good faith and follow this policy, we won’t pursue legal action against you for your research, and we’ll consider it authorised. Good faith means you:

  • only access what you need to show the issue exists, and don’t view, change, keep or share other people’s data,
  • don’t disrupt our services (no denial-of-service, spam or heavy automated testing),
  • don’t use social engineering, phishing or physical attacks against us or our providers,
  • give us reasonable time to fix the issue before telling anyone else.
§ 4

Scope

In scope: ornislabs.com and its pages. Systems run by our service providers are covered by their own policies; if you find an issue there, please report it to them.

Version history · version 1, effective 3 October 2026