Skip to content

Security & responsible disclosure

Found a problem?
Let’s make it right.

How to report a security vulnerability in OpenAlly, what to expect after you report one, and what is out of scope.

Report a vulnerability

A useful report starts here

Help us
reproduce it.

The more concrete the reproduction, the faster we can understand the problem.

Email a security report
  1. 01

    What you found

    The affected feature and the behaviour you observed.

  2. 02

    How to reproduce it

    Clear steps and a proof of concept, if you have one.

  3. 03

    What the impact is

    What an attacker could do with the issue.

Test with care.

Use your own accounts, devices and data. Stop once you’ve demonstrated the problem and give us a reasonable chance to fix it.

Reporting guidelines

Respect the boundary.

No access to other people’s data, denial of service, automated scanning, phishing or social engineering.

What to avoid

We acknowledge reports and prioritise by potential harm. There is no paid bounty or fixed remediation deadline.

The full document

Security

Last updated: July 2026

How to report

What happens next

Please do

Please do not

Out of scope