Coordinated Disclosure

Find a security bug? We want to hear from you.

We're a small team running a DNS filter for security professionals. Honest researchers find honest bugs — and we'd rather hear them from you than read about them in a post-mortem.

How to report

Email [email protected].

PGP key for sensitive details: fingerprint 0xABCD1234… (full key on request — we'll publish on /security/pgp once SOC 2 audit confirms our key-rotation cadence).

Include in your report:

In scope

Anything that meaningfully degrades the security of a tenant's data, the integrity of resolution, or the availability of the platform.

api.olladns.com
mcp.olladns.com
login.olladns.com
dns.olladns.com (DoH)
olladns.com (marketing)

Out of scope

CSP / HSTS / cookie-flag nitpicks without impact
Rate-limit bypass without auth bypass
Self-XSS
Reports from automated scanners with no triage
Volumetric DoS testing (please don't)
Social engineering of our team
Third-party dependencies — report to them upstream first
Recently-disclosed CVEs we're already patching

Safe harbor

If you act in good faith — test only against your own tenant, don't access other customers' data, give us reasonable time to fix before publishing — we will not pursue legal action and will defend you publicly against any third-party claim that arises from your testing.

If you accidentally access another tenant's data while reproducing a bug: stop, delete what you have, tell us. We treat that as a stronger report, not a hostile act.

What you'll hear back

Our response SLA.

1 business day

Acknowledgment

Confirmation we got the report. Not yet a triage verdict — just "received, looking at it."

5 business days

Triage verdict

Severity (Critical / High / Medium / Low / Info), in-scope confirmation, fix-target ETA. If we disagree it's in scope we'll explain why in detail.

Critical: 7 days · High: 30 days

Fix shipped

Patched in production. You get a heads-up before the changelog entry goes public so you can prep your write-up.

Within 90 days

Public disclosure window

Default coordinated-disclosure window. We'll work with you on extension if rollout to enterprise customers needs more time, or compression if active exploitation is observed.

Bounty stance

Not yet a formal bounty program.

We're a small team and a formal bounty program would attract more low-quality submissions than we can triage well. We do issue discretionary thank-you payments (typically $50–$2,000 depending on severity + report quality) and a public credit on the changelog if you want one.

We will revisit a formal program after SOC 2 Type II lands and we have headcount to run it properly.