Security

Reporting

Report vulnerabilities privately to [email protected] before any public disclosure. This covers both websites, the live services, and all projects, including software whose source has not published. Reports about pre-release software are explicitly welcome: coordinated disclosure does not wait for a repository to be public.

What to include

  • What you found and where.
  • Steps to reproduce, or enough detail to follow your reasoning.
  • Impact as you understand it.

Expectations

Best effort from a small studio, honestly stated: acknowledgement normally within a few days, a straight answer about whether and when a fix ships, and credit if you want it. No bounty programme. Please avoid disruptive testing against live services.

Machine-readable contact

/.well-known/security.txt on this domain and on oesalabs.com.

Per-project policies

Pika Suite maintains a written security policy in its repository, which publishes with it. Until then, the address above is the single door for everything.