Security Policy & Responsible Disclosure
We take the security of OGRECORDS™ seriously. Researchers who report vulnerabilities in good faith are explicitly welcome. This policy explains how to report a vulnerability and what you can expect from us.
Report a vulnerability
Send your report to: info@og-records.com
Please describe the vulnerability, the affected URLs or endpoints, and include steps to reproduce. Machine-readable contact details are in our security.txt.
Scope
In scope:
og-records.comwww.og-records.comadmin.og-records.comapi.og-records.com
Out of scope:
- Denial-of-service (DoS/DDoS) and load testing
- Social engineering, phishing against staff or users
- Physical access to facilities or hardware
- Spam or best-practice-only notes without demonstrable security impact (e.g. missing headers without an exploit)
- Third-party services, platforms or dependencies
Safe harbor
As long as you follow this policy, we consider your research authorized. We will not pursue legal action against you and will work with you toward a timely fix. We will not hold accidental, good-faith violations against you.
What we ask of you
- Only use your own test accounts and data.
- Do not exfiltrate, modify or delete data.
- Do not violate the privacy of others.
- Do not disrupt or degrade the service.
- Give us reasonable time to remediate before disclosing details publicly.
What you can expect from us
- Acknowledgement within 3 business days.
- Status updates while we work on it.
- Prioritized remediation of critical issues.
- Recognition at your discretion.
Recognition
We do not currently run a paid bug-bounty program. On request, we will publicly credit you as the finder once the issue is fixed.