Safety
Report a vulnerability
If you find a security vulnerability in optes3.com, the OPTES app or its API, tell us before anyone else. We thank everyone who reports responsibly.
What we need in your message
The affected link or component, the steps to reproduce it, the impact you expect, and any screenshot or request that shows it. Start the subject line with the word “Vulnerability”.
What we commit to
We confirm we received your message, aim to reply within five working days, and tell you when what you reported is fixed. We will not pursue anyone who follows the rules below in good faith.
Testing rules
Don’t access or change other people’s data, don’t disrupt the service or flood it with requests, and don’t use social engineering or physical access. Test with your own account only.
Disclosure
Give us 90 days, or until the issue is fixed, before you publish any details. We will name you in our thanks if you wish.
The security.txt carries the same contact for researchers’ tools. We have no published bug bounty program at this time.