SECURITY · 04
Report a security issue.
This disclosure process covers the public ontos.ws website. We welcome clear, good-faith reports that help us protect the site and its visitors.
Report a vulnerability
Email security@ontos.ws with the affected URL, a concise description, reproduction steps, potential impact, and any supporting evidence. Remove personal data that is not necessary for the report.
Research boundaries
- Do not access, modify, retain, or destroy another person's data.
- Do not use denial of service, social engineering, phishing, physical intrusion, or destructive testing.
- Do not disrupt availability or degrade the experience for other visitors.
- Stop testing and report promptly if you encounter sensitive information.
What to expect
Ontos will aim to acknowledge a credible report within five business days, investigate according to risk, and communicate material progress when practical. Please allow reasonable time for remediation before publishing details.
Good-faith research
Ontos will not initiate legal action solely for accidental, good-faith research that follows these boundaries. This statement does not authorise testing of third-party services, physical products, private systems, or infrastructure not controlled by Ontos.
Machine-readable policy
The standard disclosure file is available at /.well-known/security.txt.