Security & Responsible Disclosure

The security of the OptiWize platform and our customers' data is a priority. If you discover a vulnerability we ask you to report it responsibly.

Contacts

What to include in your report

  • Technical description of the vulnerability
  • Reproducible steps or proof-of-concept
  • Affected version/endpoint
  • Estimated impact

What you can expect

  • Acknowledgement within 3 business days
  • Status update within 14 days
  • No legal action for good-faith research that follows this policy

Out of scope

  • Load/DoS testing, social engineering, physical attacks
  • Known dependency vulnerabilities with no exploitable impact on OptiWize
  • Low severity issues (e.g. missing security headers on static assets)
Security — OptiWize