Security and Vulnerability Disclosure
How to report vulnerabilities privately, what testing is in scope, and how Oculve responds to good-faith research.
Last updated: June 2026
1. Private reporting options
Security researchers can contact us at [email protected]. If our /.well-known/security.txt lists additional instructions or an encryption key, use them when appropriate.
You may report under a pseudonym. We only need enough detail to understand and reproduce the issue.
2. Good-faith testing
We support responsible testing of systems you can lawfully access, provided you avoid privacy harm, service degradation, persistence, or lateral movement beyond what is necessary to prove impact.
3. Out of bounds
Do not exfiltrate user data, attack third-party vendors, perform denial-of-service testing, send spam through the platform, or publicly disclose an issue before coordinated disclosure is possible.
4. What to send
Helpful reports include the affected component, reproduction steps, expected and actual results, impact, prerequisites, and a sanitized proof of concept.
Please minimize or redact personal data. A proof is more valuable than a data dump.
5. What to expect from us
We aim to acknowledge credible reports, investigate them, and keep communication practical.
Remediation timing depends on severity, exploitability, and third-party dependencies, but good-faith reporting will not require you to reveal more identity information than necessary.