Security Policy & Responsible Disclosure

We take the security of OGRECORDS™ seriously. Researchers who report vulnerabilities in good faith are explicitly welcome. This policy explains how to report a vulnerability and what you can expect from us.

Report a vulnerability

Send your report to: info@og-records.com

Please describe the vulnerability, the affected URLs or endpoints, and include steps to reproduce. Machine-readable contact details are in our security.txt.

Scope

In scope:

Out of scope:

Safe harbor

As long as you follow this policy, we consider your research authorized. We will not pursue legal action against you and will work with you toward a timely fix. We will not hold accidental, good-faith violations against you.

What we ask of you

What you can expect from us

Recognition

We do not currently run a paid bug-bounty program. On request, we will publicly credit you as the finder once the issue is fixed.