OrbitAlert
Sign in →

Security

Security Disclosure Policy

Last updated: 8 July 2026. We don't run a paid bug bounty program today, but we take every good-faith report seriously and commit to the process below.

How to Report

Email us directly — do not open a public GitHub issue or post about an unpatched vulnerability publicly.

Email: security@orbitalert.net

Subject line: “Security Report”

Include: steps to reproduce, affected endpoint/component, and potential impact. A proof-of-concept is helpful but not required.

If you need to share sensitive details (e.g. a working exploit), say so in your first email and we'll arrange a secure channel.

What to Expect

  • Acknowledgement: within 2 business days.
  • Initial assessment (severity, whether it's in scope): within 5 business days.
  • Status updates: at least every 2 weeks while a valid report remains open, until it's resolved.
  • Fix timeline: depends on severity — critical issues affecting customer data are prioritized immediately; we don't commit to a fixed SLA for lower-severity findings, but we will tell you our plan.

We'll credit you (with your permission) once a fix ships, if you'd like public acknowledgement.

Scope

In scope:

  • The API at api.orbitalert.net and the dashboard web application.
  • Authentication, authorization, and multi-tenant data isolation (e.g. accessing another organization's data).
  • Webhook delivery, signature verification, and SSRF protections.
  • Billing/payment flow integrity (not card data itself — that never touches our servers).

Out of scope:

  • Denial-of-service or load-testing attacks — don't run these against production.
  • Social engineering, phishing, or physical attacks against staff.
  • Findings that require physical access to a user's device.
  • Reports generated purely by automated scanners without manual verification of impact.
  • Third-party services we depend on (report those directly to the vendor) — see our sub-processor list.
  • Missing security headers or best-practice deviations with no demonstrated exploit path.

Safe Harbor

We will not pursue legal action against you, and consider your research authorized, if you:

  • Make a good-faith effort to avoid privacy violations, data destruction, and service disruption.
  • Only interact with accounts and data you own, or for which you have explicit permission.
  • Do not exploit a vulnerability beyond what's necessary to confirm it (e.g. stop after proving data access is possible — don't exfiltrate it).
  • Report the issue to us promptly and don't disclose it publicly before we've had a reasonable opportunity to fix it (coordinated disclosure — typically 90 days, negotiable based on severity and fix complexity).
  • Comply with applicable law.

If a third party brings a legal claim against you for activity conducted in line with this policy, we will make clear that your actions were authorized.

No Bounty Program (Yet)

We do not currently offer paid bounties for vulnerability reports. This is a size-of-company constraint, not a statement that reports aren't valued — every report is read by an engineer, and we'd rather have a documented, honest policy without a bounty than a bounty program we can't properly fund. This may change as we grow; check back or ask.

See also Security, Compliance, and Status.