Report vulnerabilities privately.
Do not place secrets or active exploit details in a general product report. Use the dedicated security contact for sensitive findings.
Responsible disclosure
Email security@opensoftware.co with a concise description, affected surface, reproduction conditions, and a safe proof of concept. Avoid accessing data that is not yours or disrupting production services.
What happens next
Potential security reports are restricted for owner or administrator review. We may ask for additional evidence through a private channel before confirming impact or remediation.
Secrets
Never submit passwords, session cookies, API keys, access tokens, private keys, or real customer records. Redact sensitive values from screenshots, logs, and recordings.