Security and Vulnerability Disclosure

Our Commitment

Online Safety values good-faith security research that helps protect readers, contributors, sources, and systems. This policy explains how to report a suspected vulnerability in technology controlled by Online Safety and the conditions under which authorized research will be treated as good faith.

This policy is not permission to access third-party systems, disrupt service, obtain unrelated data, or break applicable law. When uncertain, stop testing and contact security@onlineSafety.org before proceeding.

Scope

In scope are onlineSafety.org and subdomains, applications, or services that Online Safety expressly identifies as controlled by it. Third-party hosting, analytics, payment, advertising, content-delivery, social-media, email, or embedded services are outside scope unless Online Safety explicitly confirms otherwise.

If a report concerns a third-party provider but materially affects Online Safety users, send a minimal description. We may coordinate with the provider, but this policy cannot authorize research against that provider.

Good-Faith Research Conditions

A researcher should make a genuine effort to avoid privacy violations, data destruction, service degradation, financial harm, and access beyond what is necessary to demonstrate the issue. Use the smallest possible proof, stop when sensitive data is encountered, and do not retain or share data that is not needed for the report.

Do not exploit a vulnerability beyond verification. Do not establish persistence, pivot to other systems, alter content, access private editorial material, read source communications, download databases, perform denial-of-service testing, send spam, conduct phishing or social engineering, test physical security, upload malware, or demand payment as a condition of non-disclosure.

Safe-Harbor Statement

When research is conducted in good faith, remains within this policy, avoids unnecessary harm, and is reported promptly, Online Safety will not initiate legal action solely because the researcher performed that authorized activity. If a third party initiates action and the research complied with this policy, we may clarify that the activity was conducted under our disclosure process where appropriate and lawful.

This safe-harbor statement does not bind third parties or law-enforcement authorities, and it does not protect conduct that is malicious, extortionate, reckless, outside scope, or unlawful for reasons unrelated to the security research.

How to Report

Send reports to security@onlineSafety.org with the subject line “Security vulnerability report”. Include the affected URL or asset, vulnerability type, steps to reproduce, observed and potential impact, date and time, browser or tool information, proof that minimizes exposure, and any suggested remediation.

Do not attach large databases, private messages, identity documents, credentials, or unnecessary personal data. Request an encrypted channel before sending sensitive evidence. A valid /.well-known/security.txt file should provide the current contact, policy URL, preferred language, and expiry date.

Response Targets

We aim to acknowledge a credible report within three business days, provide an initial assessment within ten business days, and communicate material status changes while remediation is underway. These are targets, not guarantees. Complex issues, third-party dependencies, holidays, or active incidents may require more time.

We prioritize vulnerabilities according to exploitability, affected data, user impact, privilege required, scope, persistence, and availability of mitigations.

Coordinated Disclosure

Researchers should allow a reasonable remediation period before public disclosure. We will discuss a proposed timeline in good faith. Immediate public disclosure may be justified where users face active harm and the publisher is unresponsive, but unnecessary disclosure of exploit details or personal data can increase risk.

We may credit a researcher with consent after remediation. We do not promise payment, a bounty, employment, or public recognition unless agreed in writing before the claim is made.

Out-of-Scope Findings

Generally out of scope are missing security headers without a demonstrated impact; clickjacking on pages without sensitive actions; self-XSS; rate-limit observations without meaningful exploitation; automated scanner output without validation; username enumeration with no additional impact; email authentication observations without evidence of exploitability; and vulnerabilities solely in an unsupported third-party component not controlled by Online Safety.

We may still review an out-of-scope issue if it presents credible risk.

Incident and Privacy Handling

Security reports are shared only with people and providers who need the information for assessment, remediation, legal compliance, insurance, or incident response. Records may be retained for security, accountability, and legal purposes. Personal data is minimized and handled under the Privacy Policy.

Contact

Security reports: security@onlineSafety.org

Privacy concerns unrelated to a vulnerability: privacy@onlineSafety.org

Editorial safety or source-security concerns: editorial@onlineSafety.org