Skip to content
Cookies

We value your privacy

With your permission, we use analytics cookies to understand how visitors use our website and how they found us. This helps us improve the website. You can change your choice at any time. See our Cookie Policy for details.

Cookie preferences

Choose what you allow

Necessary

Your theme, language and this choice, kept in your browser's local storage. Never used to track you. Always on.

Analytics

Google Analytics: which pages are read, how visitors found us, and which pages lead to a demo request.

No consent stored yet.Cookie Policy
Otector
HomePlatformAsset OwnersService ProvidersSecurityAbout
Book a demo
HomePlatformFor Asset OwnersFor Service ProvidersSecurity & ArchitectureAboutBook a demo
Legal

Responsible Disclosure

Last updated · September 2026

Security is central to what we build. If you believe you have found a vulnerability in our website or services, we welcome your report and will work with you to resolve it responsibly.

How to report a vulnerability

Email security@otector.io with a clear description of the issue. Please give us reasonable time to investigate and remediate before any public disclosure.

What to include in your report

  • A description of the vulnerability and its potential impact
  • Steps to reproduce, including affected URLs or components
  • Any proof-of-concept material that helps us understand the issue
  • How we can contact you for follow-up

What we ask from researchers

  • Act in good faith and avoid privacy violations or service disruption
  • Only test against your own accounts or data, never other users'
  • Do not exfiltrate data, and delete any incidental data you encounter
  • Give us a reasonable window to remediate before disclosure

What you can expect from us

  • An acknowledgement of your report
  • An honest assessment and, where valid, a plan to remediate
  • Updates on progress as we work through the issue
  • Recognition of your contribution, if you wish

Out-of-scope activities

  • Denial-of-service or volumetric testing
  • Social engineering of staff, customers or partners
  • Physical attacks or attempts to access facilities
  • Automated scanning that degrades service

Contact

Send reports to security@otector.io. We do not currently operate a paid bug bounty programme.

Otector

Secure remote access for operational technology environments, with approvals, monitoring, recordings and audit evidence under your control.

Get in touch
contact@otector.ioLinkedIn
01Product
Platform
  • Platform
  • Controlled Tunnels
  • Secure File Transfer
  • Book a demo
02Solutions
For teams
  • Asset Owners
  • Service Providers
Common challenges
  • Vendor Remote Access
  • Replace VPN Access
  • Maintenance Access
03Industries
By industry
  • Industries Overview
  • Manufacturing
  • Pharma
  • Water Utilities
  • Energy & Utilities
  • Healthcare
  • Food & Beverage
04Trust
Security & compliance
  • NIS2 Remote Access
  • Security Architecture
  • Audit Remote Access
  • Responsible Disclosure
Architecture topics
  • Outbound-only access
  • Session evidence
  • Service-provider governance
05Company
Company
  • About
  • Partners
  • Contact
  • LinkedIn
06Legal
Legal
  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy
  • Company details
© 2026 Otector B.V. All rights reserved.Designed with industrial security principles in mind