Security & Responsible Disclosure
Last updated: 7 July 2026
Found a vulnerability? Please tell us before disclosing it publicly. Email security@omegapointsolutions.com.
1. Reporting a vulnerability
Email security@omegapointsolutions.com with a clear description, steps to reproduce, and the impact. Please give us a reasonable time to investigate and fix before any public disclosure.
2. Good-faith safe harbor
We will not pursue action against researchers who, in good faith: test only against their own accounts/sensors; avoid privacy violations, data destruction, and service disruption; do not access or exfiltrate other users' data; and give us time to remediate. Do not run automated scans that degrade the Service.
3. Out of scope
- Denial-of-service or volumetric testing.
- Social engineering of staff or users.
- Reports from automated scanners without a demonstrated, reproducible impact.
- Third-party services (Stripe, Cloudflare) — report those to the respective vendor.
4. Our practices
- Sovereign, thin-sensor design: sensors hold only a revocable credential and can only submit observations; all scoring stays server-side.
- Member and sensor tokens are stored hashed, never in plaintext; the public tip line is protected by a bot-check and rate limits.
- Encryption in transit; least-privilege access; secrets kept out of source control.
Contact
Security: security@omegapointsolutions.com · General: crose@omegapointsolutions.com
Omega Point Threat ID