← Back to Home

Responsible Disclosure

As a security research organization, we take the security of our own infrastructure seriously. If you've discovered a vulnerability in ODINT's systems, we want to hear about it. We commit to working with security researchers who report vulnerabilities responsibly.

Report a Vulnerability

For security-related issues with ODINT infrastructure:

[email protected]

Please include "SECURITY" in the subject line

Scope

In Scope

  • odint.io website and subdomains
  • Our public-facing web applications
  • API endpoints (when available)
  • SecureDrop instance (when operational)
  • Authentication and authorization issues
  • Data exposure vulnerabilities

Out of Scope

  • Social engineering attacks against our team
  • Physical attacks against our infrastructure
  • Denial of service attacks
  • Third-party services we use (report to them directly)
  • Issues requiring physical access
  • Spam or phishing

What to Include

When reporting a vulnerability, please include:

Our Commitment

When you report a vulnerability to us, we commit to:

Important

Please do not publicly disclose vulnerabilities until we've had reasonable time to address them. We ask for a minimum of 90 days before public disclosure.

Safe Harbor

We consider security research conducted in accordance with this policy to be authorized. We will not pursue legal action against researchers who:

Note

This page is for reporting security issues with ODINT's own infrastructure. If you want to report exposed government infrastructure you've discovered, please visit our Submit a Tip page instead.