OpsRabbit Trust Center

Vulnerability Disclosure Policy

A safe route for reporting potential security issues in OpsRabbit.

PublicVersion 1.0September 2026

Overview

This policy provides a safe, coordinated path for reporting a suspected security issue affecting OpsRabbit. It is intended for good-faith research performed without accessing customer environments, disrupting service or retaining data.

The policy defines eligible testing, prohibited activity, report contents, triage and coordinated disclosure expectations.

How to report

Email info@OpsRabbit.io with “Security vulnerability report” in the subject. Include the affected component, reproducible steps, potential impact and safe supporting evidence. Do not include customer data, credentials or unnecessary personal data.

Research guidelines

  • Act in good faith and avoid privacy violations, data destruction, service disruption, social engineering and physical attacks.
  • Use only accounts and data you own or are explicitly authorized to test.
  • Stop and report if you encounter customer data or obtain unintended privileged access.
  • Allow reasonable time for investigation and remediation before public disclosure.

Our response

OpsRabbit provider will acknowledge reports when practicable, triage severity, coordinate remediation and communicate status appropriate to the risk. This policy does not authorize testing of third-party services and does not promise a bounty.

In-scope testing

Good-faith research should be limited to publicly accessible OpsRabbit assets or a researcher-owned authorized tenant. Testing of customer-hosted environments, customer integrations, third-party providers, employees, offices or data is out of scope unless OpsRabbit provider and the affected owner provide written authorization.

Prohibited activity

  • Denial of service, traffic flooding or resource exhaustion
  • Accessing, modifying, retaining or disclosing data that does not belong to the researcher
  • Social engineering, phishing, physical intrusion or employee targeting
  • Destructive testing, malware deployment or persistence
  • Automated scanning that materially degrades service
  • Public disclosure before coordinated remediation

Report handling

Reports are logged, screened for scope and reproducibility, assigned a severity based on realistic impact and exposure, and routed to an owner. OpsRabbit provider may request clarification or a safe, non-destructive demonstration. Status communication depends on risk and investigation needs. Duplicate, theoretical, informational or third-party-only reports may be closed without remediation.

Safe-harbor intent

OpsRabbit provider does not intend to pursue action against researchers who act in good faith, comply with this policy, avoid privacy harm and provide reasonable time to remediate. This statement does not bind third parties, waive legal rights, authorize unlawful activity or create a promise of compensation.