Security Vulnerability
Reporting Guidelines
Thank you for working with Onapsis to help ensure we can provide a timely response to any security issues in our products. We are committed to working with researchers to fully understand an issue and providing a resolution to resolve it.
To ensure that we have the information required to properly evaluate a reported issue, Onapsis asks that you include the following information in any bug report:
Out-of-Scope
The following list of security issues won’t be accepted as a valid report.
Vulnerabilities in older application/package/library versions.
Security-headers-related issues.
Transport Layer Security configuration issues.
Brute force attacks.
Attacks that require social engineering.
During the evaluation process, Onapsis will keep you updated on our status for resolving the issue.
If you are an Onapsis customer or partner, please use the Customer Portal to submit a service request for any security vulnerability you believe you have discovered in Onapsis products. If you are not a customer or partner, please email [email protected] with your discovery. We encourage using email encryption with our encryption key when emailing Onapsis Security.
