Responsible Disclosure
Placeholder draft · Last updated 6 July 2026
Placeholder draft — this document has not yet completed legal review and is not legal advice. Final text must be reviewed before client contracting.
1. Reporting a vulnerability
If you believe you have found a security vulnerability in OgmaQ, please report it to [email protected]. If you receive no acknowledgement, [email protected] reaches the same team. Machine-readable contact details are published at /.well-known/security.txt.
2. What to include
- A description of the issue and where you found it (URL, endpoint or feature).
- Steps to reproduce, or a proof of concept.
- The potential impact as you understand it.
- How we can reach you for follow-up questions.
3. Please avoid
- Accessing, modifying or exfiltrating data that belongs to other tenants or users — if you can see another tenant's data, stop and report it.
- Actions that could disrupt the service for others (denial of service, resource exhaustion, spam).
- Social engineering, phishing or physical attacks against OgmaQ or its users.
4. What to expect
We aim to acknowledge your report within 5 business days. This is an operational target, not a contractual commitment. We will keep you informed as we investigate and remediate, and we are happy to credit researchers who wish to be named once a fix is in place.
5. Safe harbor
Placeholder: OgmaQ intends to support good-faith security research conducted within these guidelines and does not intend to pursue legal action against researchers who follow them; the formal safe-harbor wording is pending legal review.