Vulnerability Disclosure
We take the security of our software and services seriously. If you believe you have discovered a security vulnerability, we encourage you to report it to us responsibly. We will review your report, investigate the issue, and work with you to address the vulnerability as quickly as possible.
Note: We will not respond to reports generated solely by AI tools or automated systems unless they include clear, human-verified evidence and reproducible steps.
This is not a bug bounty program
We really appreciate your reports, but we cannot provide financial compensation for reported security vulnerabilities. So this page is not to be misinterpreted as a bug bounty program.
How to report
Please send your report to security@ownbit.net.
To help us investigate the issue, please include:
- A clear description of the vulnerability
- The affected product, service, component including the version
- Steps to reproduce the issue
- The potential security impact
- Any proof-of-concept or relevant technical details
- Your contact information, if you would like us to follow up with you
Please do not include sensitive personal data or credentials unless they are strictly necessary to demonstrate the vulnerability.
Responsible disclosure
We kindly ask you to give us a reasonable amount of time to investigate and remediate reported vulnerabilities before making them public.
Please avoid:
- Accessing, modifying, or deleting data that does not belong to you
- Disrupting our services or degrading their availability
- Performing actions that could harm our users or systems
- Accessing or exfiltrating more data than necessary to demonstrate the vulnerability
- Publicly disclosing a vulnerability before we have had a reasonable opportunity to address it
If you unintentionally encounter sensitive data while researching a vulnerability, please stop testing and let us know immediately.
Thank you very much!