Security & Responsible Disclosure
The security of the OptiWize platform and our customers' data is a priority. If you discover a vulnerability we ask you to report it responsibly.
Contacts
- Primary email: [email protected]
- Backup: [email protected]
- Machine-readable
/.well-known/security.txt
What to include in your report
- Technical description of the vulnerability
- Reproducible steps or proof-of-concept
- Affected version/endpoint
- Estimated impact
What you can expect
- Acknowledgement within 3 business days
- Status update within 14 days
- No legal action for good-faith research that follows this policy
Out of scope
- Load/DoS testing, social engineering, physical attacks
- Known dependency vulnerabilities with no exploitable impact on OptiWize
- Low severity issues (e.g. missing security headers on static assets)