Security & responsible disclosure
Found a problem?
Let’s make it right.
How to report a security vulnerability in OpenAlly, what to expect after you report one, and what is out of scope.
Report a vulnerabilityA useful report starts here
Help us
reproduce it.
The more concrete the reproduction, the faster we can understand the problem.
Email a security report- 01
What you found
The affected feature and the behaviour you observed.
- 02
How to reproduce it
Clear steps and a proof of concept, if you have one.
- 03
What the impact is
What an attacker could do with the issue.
Test with care.
Use your own accounts, devices and data. Stop once you’ve demonstrated the problem and give us a reasonable chance to fix it.
Reporting guidelinesRespect the boundary.
No access to other people’s data, denial of service, automated scanning, phishing or social engineering.
What to avoidWe acknowledge reports and prioritise by potential harm. There is no paid bounty or fixed remediation deadline.
The full document
Security
Last updated: July 2026
How to report
Email support@openally.ai with "security" in the subject line. The same address is published in machine-readable form at /.well-known/security.txt.
Please include what you found, the steps to reproduce it, and what an attacker could do with it. A proof of concept helps enormously. If a report is ambiguous we will ask rather than guess, so the more concrete the reproduction, the faster it moves.
What happens next
We acknowledge reports and work through them in order of how much harm they can do. We will tell you what we concluded, including when we decide something is not a vulnerability and why.
We do not run a paid bug bounty and we would rather say so plainly than leave it implied. There is no reward, and no fixed remediation deadline we can honestly commit to.
Please do
- Test only against your own account, your own device, and data you own.
- Give us a reasonable chance to fix an issue before you publish it.
- Stop as soon as you have shown a problem exists. Do not go further into an account or a device that is not yours to measure how bad it is, tell us instead.
Please do not
- Access, modify, or delete data belonging to anyone else, or degrade service for anyone else.
- Run denial-of-service, load, or automated scanning traffic against our endpoints.
- Use social engineering, phishing, or physical access against our staff or our users.
Out of scope
Reports that amount to a scanner's output with no demonstrated impact, missing security headers with no exploit path, and issues in third-party services we do not operate are out of scope. For a third-party service, please report it to whoever runs it. We will help you find the right contact if that is not obvious.
An app running on a device the user controls is not a boundary we claim to defend: the device owner can already read and change what is on their own device, and that is by design rather than a flaw.
