Responsible disclosure
Security reporting
Please report suspected vulnerabilities privately and provide only the information needed to reproduce and assess the issue.
Email the security report
Send security-sensitive reports to [email protected] with the subject “OpenForBots security report.” Do not include credentials, private network information, personal data, or unreleased product information unless it is strictly necessary to explain the issue.
Machine-readable policy
Security contacts, policy location, preferred language, canonical location, and expiry are also published at /.well-known/security.txt.
Include
- a concise description of the suspected vulnerability;
- the affected route, component, or request flow;
- reproduction steps using non-sensitive test data;
- the potential impact and any known mitigations;
- a safe way to contact the reporter by email.
Testing boundaries
Do not disrupt service availability, access private data, test third-party websites without authorization, bypass rate limits, or use automated scanning that creates excessive traffic.
Response expectations
OpenForBots will review reports as capacity permits. Submission does not create a bounty, payment obligation, service-level commitment, or guarantee of a particular remediation timeline.
Last updated: .