DISCLOSURE

    Responsible Disclosure

    Found a security issue in Onyx itself? We want to hear from you — privately.

    Effective date: [Effective Date] · Operated by [Legal Entity Name]

    Draft — not legal advice. This document is a good-faith description of our practices and is being finalized. Bracketed fields (e.g. [Jurisdiction]) still need to be completed.

    Report privately

    If you discover a vulnerability in Onyx, please report it privately to security@[your-domain] and give us a reasonable opportunity to fix it before any public disclosure. Please do not open a public GitHub issue for security reports, as that discloses the vulnerability to everyone before a fix is available.

    Safe harbor

    We will not pursue or support legal action against researchers who, in good faith:

    • Make a genuine effort to avoid privacy violations, data destruction, and service disruption.
    • Only interact with accounts they own or have explicit permission to access.
    • Give us reasonable time to remediate before disclosing publicly.
    • Do not exfiltrate data beyond the minimum needed to demonstrate the issue.

    Good-faith research conducted consistently with this policy is considered authorized. If in doubt, ask us first at security@[your-domain].

    In scope

    • The Onyx web application and its API.
    • Authentication, authorization, and access-control issues.
    • Handling of secrets, tokens, and scan evidence.
    • Bypasses of the SSRF guard or domain-ownership verification.

    Out of scope

    • Findings that require access to a user’s device or physical access.
    • Social engineering, spam, or denial-of-service testing against our infrastructure.
    • Reports from automated scanners without a demonstrated, exploitable impact.
    • Issues in third-party services we use (report those to the respective vendor).

    What to include

    • A clear description of the issue and its impact.
    • Step-by-step reproduction, including any proof-of-concept.
    • Affected URLs, endpoints, or components.

    What to expect

    We aim to acknowledge reports promptly and to keep you updated as we investigate and remediate. [State your target acknowledgement/response window, e.g. 3 business days.] We’re a small team and appreciate your patience and discretion.

    Contact

    Security reports: security@[your-domain]. For non-security questions, use the channels on our other pages.