L/07Legal
Vulnerability Disclosure Policy
We welcome reports from security researchers and from anyone who finds a security issue in our systems. This policy explains what is in scope, how to report and what you can expect from us.
- Document
- Vulnerability Disclosure Policy
- Last updated
- 22 September 2026
- Applies to
- www.onioninfosec.com
On this page
1. Scope
This policy applies to the following systems.
- The website at onioninfosec.com, including www.onioninfosec.com, and the form functions that run on the same domain
Our products
Our security products are in development and are out of scope of this policy until they are released. We will update the scope when that changes.
Systems we do not own
Systems operated by third parties, including organizations we work with, suppliers and hosting providers, are not covered. We cannot authorize testing of systems we do not own. If you find an issue in a third-party service, report it to that party.
2. Out of scope
The following activities and report types are outside this policy.
- Denial of service, load testing or any activity that degrades the website for others
- Social engineering of our staff, contractors or clients, including phishing
- Physical access to offices, devices or facilities
- Testing of third-party services, including the hosting platform itself
- Output from automated scanners that has not been validated to show a real, exploitable issue
- Reports with no security impact, such as missing best-practice settings with no demonstrated consequence
- Spam or volume testing of the contact form
3. Rules for research
To stay within this policy, we ask you to:
- access only the minimum data needed to demonstrate the issue
- stop and report at once if you encounter personal data or confidential information, and not copy, keep or disclose it
- not modify or delete data, and not degrade the service
- not use a finding to move further into our systems or to reach other systems
- use only accounts and data that you own or have permission to use
- keep the details confidential until we have resolved the issue or agreed a disclosure date with you
- comply with the laws that apply to you
4. How to report
Send reports to security@onioninfosec.com. If a report includes sensitive details, describe the issue in general terms first and we will arrange a suitable channel for the rest. Contact details are also published at /.well-known/security.txt.
A useful report includes the following.
- The affected address, system or component
- The type of vulnerability and its likely impact
- Step-by-step instructions to reproduce it, with any proof-of-concept code, requests or screenshots
- The date and time of your testing and the IP address you tested from, so we can find it in logs
- Whether the issue is already public or has been reported to anyone else
- How you would like to be contacted and whether you want to be credited
5. Our commitments
When you report an issue under this policy, we will:
- acknowledge your report within 7 business days
- assess the report and tell you whether we can reproduce the issue
- keep you informed of progress until the issue is resolved or closed
- tell you when the issue has been fixed, and invite you to confirm the fix if you wish
- treat your report and your identity as confidential unless you agree otherwise or the law requires disclosure
6. Safe harbor for good-faith research
If you make a good-faith effort to follow this policy, we will treat your research on the systems in scope as authorized by us. We will not start or support legal action against you for that research, or for an accidental breach of this policy made in good faith.
If a third party brings legal action against you for activity that followed this policy, we will make it known that your actions were carried out under this policy.
This commitment covers Onion Infosec only. We cannot bind third parties, regulators or law enforcement bodies, and we cannot authorize activity that the law prohibits. If you are unsure whether an action is within this policy, ask us before you continue.
7. Coordinated disclosure
We ask that you give us a reasonable opportunity to fix an issue before you publish or share details. We will agree a disclosure date with you where you intend to publish. If a fix needs more time, we will explain why and agree a new date with you.
Please do not publish personal data, credentials or client information in any circumstances.
8. No bug bounty at present
We do not run a bug bounty programme at present, and we do not offer monetary rewards for reports. Please do not make a report conditional on payment.
9. Recognition
With your permission, we will thank you publicly, by name or handle, once a valid issue you reported has been fixed. You can also ask to remain anonymous.
10. Vulnerabilities we find in other products
This policy covers reports made to us. When our own research team finds a vulnerability in a product from another organization, we follow coordinated disclosure with the owner. See Security Labs.
