Legal
Responsible Disclosure
Last updated · September 2026
Security is central to what we build. If you believe you have found a vulnerability in our website or services, we welcome your report and will work with you to resolve it responsibly.
How to report a vulnerability
Email security@otector.io with a clear description of the issue. Please give us reasonable time to investigate and remediate before any public disclosure.
What to include in your report
- A description of the vulnerability and its potential impact
- Steps to reproduce, including affected URLs or components
- Any proof-of-concept material that helps us understand the issue
- How we can contact you for follow-up
What we ask from researchers
- Act in good faith and avoid privacy violations or service disruption
- Only test against your own accounts or data, never other users'
- Do not exfiltrate data, and delete any incidental data you encounter
- Give us a reasonable window to remediate before disclosure
What you can expect from us
- An acknowledgement of your report
- An honest assessment and, where valid, a plan to remediate
- Updates on progress as we work through the issue
- Recognition of your contribution, if you wish
Out-of-scope activities
- Denial-of-service or volumetric testing
- Social engineering of staff, customers or partners
- Physical attacks or attempts to access facilities
- Automated scanning that degrades service
Contact
Send reports to security@otector.io. We do not currently operate a paid bug bounty programme.