1. Our Commitment
Security is architectural at OSG, not a marketing layer. We take reports of potential vulnerabilities seriously and are committed to working with security researchers to understand and address issues responsibly.
2. Scope
This policy covers OSG's public-facing website and platform infrastructure. [Specific in-scope and out-of-scope systems to be finalized — e.g. whether this extends to customer-deployed instances, third-party integrations, or is limited to OSG-operated infrastructure.]
3. How to Report
If you believe you've found a security vulnerability, please report it to us directly rather than disclosing it publicly. Include:
- A description of the vulnerability and its potential impact
- Steps to reproduce, including any proof-of-concept
- The affected system or URL
Report to: [security contact email to be finalized]
PGP key (optional): [to be published if applicable]
4. Our Response
We aim to acknowledge reports within [response time to be finalized — e.g. 2 business days] and to provide an initial assessment within [timeframe to be finalized]. We'll keep you informed as we work toward resolution.
5. Safe Harbor
We will not pursue legal action against researchers who: report vulnerabilities in good faith through the channel above, avoid privacy violations and service disruption, and give us reasonable time to remediate before any public disclosure. [Full safe-harbor language to be finalized with counsel.]
6. What We Ask You Not to Do
- Do not access, modify, or delete data that isn't yours
- Do not perform testing that could degrade service for others
- Do not publicly disclose a vulnerability before we've had the opportunity to address it
7. Recognition
[Whether OSG intends to offer public recognition, a bug bounty, or other acknowledgment for valid reports is to be decided and stated here.]