1. Our Commitment

Security is architectural at OSG, not a marketing layer. We take reports of potential vulnerabilities seriously and are committed to working with security researchers to understand and address issues responsibly.

2. Scope

This policy covers OSG's public-facing website and platform infrastructure. [Specific in-scope and out-of-scope systems to be finalized — e.g. whether this extends to customer-deployed instances, third-party integrations, or is limited to OSG-operated infrastructure.]

3. How to Report

If you believe you've found a security vulnerability, please report it to us directly rather than disclosing it publicly. Include:

Report to: [security contact email to be finalized]

PGP key (optional): [to be published if applicable]

4. Our Response

We aim to acknowledge reports within [response time to be finalized — e.g. 2 business days] and to provide an initial assessment within [timeframe to be finalized]. We'll keep you informed as we work toward resolution.

5. Safe Harbor

We will not pursue legal action against researchers who: report vulnerabilities in good faith through the channel above, avoid privacy violations and service disruption, and give us reasonable time to remediate before any public disclosure. [Full safe-harbor language to be finalized with counsel.]

6. What We Ask You Not to Do

7. Recognition

[Whether OSG intends to offer public recognition, a bug bounty, or other acknowledgment for valid reports is to be decided and stated here.]