Report privately
If you discover a vulnerability in Onyx, please report it privately to security@[your-domain] and give us a reasonable opportunity to fix it before any public disclosure. Please do not open a public GitHub issue for security reports, as that discloses the vulnerability to everyone before a fix is available.
Safe harbor
We will not pursue or support legal action against researchers who, in good faith:
- Make a genuine effort to avoid privacy violations, data destruction, and service disruption.
- Only interact with accounts they own or have explicit permission to access.
- Give us reasonable time to remediate before disclosing publicly.
- Do not exfiltrate data beyond the minimum needed to demonstrate the issue.
Good-faith research conducted consistently with this policy is considered authorized. If in doubt, ask us first at security@[your-domain].
In scope
- The Onyx web application and its API.
- Authentication, authorization, and access-control issues.
- Handling of secrets, tokens, and scan evidence.
- Bypasses of the SSRF guard or domain-ownership verification.
Out of scope
- Findings that require access to a user’s device or physical access.
- Social engineering, spam, or denial-of-service testing against our infrastructure.
- Reports from automated scanners without a demonstrated, exploitable impact.
- Issues in third-party services we use (report those to the respective vendor).
What to include
- A clear description of the issue and its impact.
- Step-by-step reproduction, including any proof-of-concept.
- Affected URLs, endpoints, or components.
What to expect
We aim to acknowledge reports promptly and to keep you updated as we investigate and remediate. [State your target acknowledgement/response window, e.g. 3 business days.] We’re a small team and appreciate your patience and discretion.
Contact
Security reports: security@[your-domain]. For non-security questions, use the channels on our other pages.