Vulnerability Disclosure Policy
Last updated: August 30, 2026
ObservSecurity welcomes reports from security researchers. This policy explains how to report a vulnerability, what we consider in and out of scope, and the protections we offer to researchers acting in good faith.
1. How to report
- Email security@observsecurity.com. For sensitive details, request our PGP key in your first message.
- Include: affected asset or URL, a clear description, reproduction steps or proof-of-concept, impact assessment, and any logs or screenshots.
- Report one vulnerability per submission unless they are related.
See also our machine-readable /.well-known/security.txt.
2. What to expect
- Acknowledgment within 3 business days.
- A triage assessment and severity rating within 10 business days.
- Regular updates until resolution, and credit in our acknowledgments if you wish.
We do not currently run a paid bug bounty. We may offer recognition or a token of thanks at our discretion.
3. Scope
In scope:
www.observsecurity.comand its subdomains that we operate- The ObservX application and its API
- The M365 Audit Tool
Out of scope:
- Third-party services we use (report those to the relevant vendor)
- Findings from automated scanners without a demonstrated, exploitable impact
- Denial of service, volumetric, or resource-exhaustion testing
- Social engineering, phishing, or physical attacks against ObservSecurity staff, users, or facilities
- Missing security headers, cookie flags, or best-practice suggestions with no concrete impact
- Reports of outdated software versions without a working exploit
- Spam, rate-limiting, or account-enumeration issues of negligible impact
4. Rules of engagement
- Only test against accounts and data you own or are explicitly authorized to use.
- Do not access, modify, or exfiltrate data that is not yours; stop immediately if you encounter customer data or personal data and report what you found.
- Do not degrade or disrupt our services or those of other customers.
- Do not use automated high-volume scanning against production.
- Give us a reasonable time to remediate before any public disclosure — we target 90 days and will coordinate timing with you.
5. Safe harbor
If you make a good-faith effort to comply with this policy during your research, we will consider your activities authorized, we will not pursue or support legal action against you (including under the Computer Fraud and Abuse Act or DMCA anti-circumvention provisions) for that research, and we will help make clear that your actions were authorized if a third party raises a concern. This safe harbor does not apply to activity that is reckless, that intentionally harms users or data, or that violates applicable law in ways unrelated to the research itself. If in doubt about whether a specific test is authorized, ask us first.
6. Legal
By submitting a report you confirm it does not include information you are prohibited from sharing, and you grant us a perpetual, royalty-free license to use the report to remediate and improve our security. This policy does not grant permission to act in any way that is inconsistent with the law or that would cause ObservSecurity to breach its own legal obligations.
Questions about this document? Email legal@observsecurity.com.