Responsible disclosure
Last updated: January 1, 2026
Offsoo considers the security of its systems important. Found a vulnerability? We would appreciate a report.
Where to report
Guidelines for responsible disclosure
We ask that you:
- do not abuse the vulnerability (do not exfiltrate data, do not make changes, do not take over accounts);
- report the problem as quickly and as completely as possible (steps to reproduce, impact, a proof of concept if available);
- do not use social engineering;
- do not carry out (D)DoS attacks or brute forcing;
- treat the report as confidential until Offsoo has resolved the problem.
Safe harbour ("no legal action")
If you act in good faith and follow the guidelines above, Offsoo will not take legal action against you for your research and your report.
How a report is handled
Offsoo will:
- confirm the report;
- assess the report and prioritise it where appropriate;
- make every effort to resolve the problem within a reasonable period;
- keep you informed of progress where appropriate.
Privacy
Process as little personal data as possible during your research, and do not include personal data in the report unless strictly necessary.