Responsible Disclosure Policy

Guidelines for reporting security vulnerabilities in OliveOps

Effective Date:
August 5, 2026
Last Updated:
August 5, 2026
Estimated Read Time:
4 min read
Version:
1.0

1. Introduction

OliveOps is committed to security and welcomes contributions from security researchers who follow responsible disclosure practices. This policy outlines how to report security vulnerabilities in OliveOps in a manner that helps us address issues quickly while protecting other users.

We appreciate good-faith efforts to discover and report security vulnerabilities. Researchers who follow this policy will be treated fairly and may receive recognition for their contributions.

2. Scope

This policy applies to security vulnerabilities in:

  • The OliveOps web application
  • The OliveOps API
  • OliveOps infrastructure and services
  • Other OliveOps-owned systems and services

This policy does not apply to third-party services, infrastructure, or code that OliveOps uses but does not own or operate (e.g., Vercel, AWS, open-source dependencies).

3. Good-Faith Research

For the purposes of this policy, good-faith research means:

  • Testing for vulnerabilities in a manner designed to discover, not exploit or harm
  • Avoiding privacy violations and unauthorized access
  • Not disrupting or degrading the availability or performance of the service for other users
  • Not accessing data belonging to other users or organizations
  • Promptly reporting vulnerabilities through proper channels
  • Avoiding public disclosure until OliveOps has had an opportunity to remediate

4. Allowed Testing Activities

You may conduct the following security research activities:

  • Manual code review and analysis
  • Testing with your own user account to discover vulnerabilities that could affect your data
  • Fuzz testing and input validation testing against OliveOps services
  • Testing for common vulnerability classes (SQL injection, XSS, CSRF, etc.)
  • Testing for authentication and authorization bypasses
  • Testing for data exposure or privacy issues
  • Testing for insecure cryptographic practices
  • Analysis of published security documentation and advisories

5. Prohibited Testing Activities

The following activities are not permitted without prior written authorization:

  • Accessing accounts or data that do not belong to you
  • Modifying or deleting data (except your own test data)
  • Accessing OliveOps' internal systems or infrastructure
  • Accessing or monitoring other users' communications
  • Using automated tools or scripts that could harm performance
  • Attempting to exploit vulnerabilities for personal gain
  • Accessing systems after discovering a vulnerability (report instead)

6. No Social Engineering

Social engineering (attempting to trick employees into revealing sensitive information or performing actions) is not permitted under this policy.

7. No Denial-of-Service Testing

Testing that results in denial-of-service (making the service unavailable to legitimate users) is prohibited. This includes:

  • Distributed denial-of-service (DDoS) attacks
  • Volumetric attacks designed to consume bandwidth or resources
  • Exhaustion attacks that overload servers or databases

If you believe you have discovered a DoS vulnerability, report it immediately without triggering the vulnerability.

8. No Privacy Violations

Do not:

  • Access or view data belonging to other users or organizations
  • Extract or copy sensitive personal or business information
  • Violate user privacy or confidentiality
  • Access health, financial, or other sensitive personal information

If you discover a privacy vulnerability that affects other users' data, report it immediately without accessing additional data.

9. How to Report Vulnerabilities

Please report security vulnerabilities directly to support@oliveops.ca.

Do not:

  • Publicly disclose the vulnerability before OliveOps has had an opportunity to remediate
  • Post vulnerabilities on public issue trackers or social media
  • Share vulnerability details with third parties without authorization
  • Report vulnerabilities through support channels (use the security email above)

Use PGP encryption for sensitive reports if available.

10. What to Include in Your Report

Provide the following information in your vulnerability report:

  • A clear description of the vulnerability
  • The type of vulnerability (e.g., SQL injection, authentication bypass)
  • The affected system, component, or endpoint
  • Steps to reproduce the vulnerability
  • The potential impact or severity of the vulnerability
  • Any proof-of-concept code or screenshots (without compromising other users' data)
  • Your contact information and public PGP key (if available)
  • The date you discovered the vulnerability

11. Our Response Process

Upon receiving a vulnerability report, OliveOps will:

  • Acknowledge receipt of your report
  • Investigate the vulnerability and assess its severity
  • Develop and test a fix
  • Deploy the fix to production
  • Notify you when the vulnerability has been remediated
  • Provide updates on our progress (if appropriate)

12. Response Timeframes

OliveOps does not guarantee specific response or remediation timeframes. Response times may vary depending on:

  • The severity and complexity of the vulnerability
  • The availability of OliveOps engineers and security team members
  • The need for additional investigation or testing
  • The need to coordinate with third-party service providers

High-severity vulnerabilities will receive priority attention. We will make good-faith efforts to remediate vulnerabilities in a reasonable timeframe.

13. Coordinated Disclosure

Once OliveOps has remediated a vulnerability, we may publish information about the issue, including:

  • A description of the vulnerability
  • The date it was discovered and fixed
  • Information about the impact and remediation
  • Attribution to the researcher (if desired)

We will coordinate the timing and content of public disclosure with you to ensure adequate time for your own disclosure or publication if desired.

14. Safe Harbour Provisions

OliveOps recognizes that good-faith security research is valuable and necessary. Provided you comply with this policy, OliveOps will not take legal action against you for:

  • Unauthorized access to OliveOps systems (only to the extent necessary to discover vulnerabilities)
  • Violation of the Computer Fraud and Abuse Act (CFAA) or similar laws (to the extent permitted by law)
  • Terms of Service violations resulting from good-faith security research
  • Disclosure of vulnerability information in accordance with this policy

Important: This safe-harbour language is subject to applicable law and does not override prohibitions against illegal activity. If you engage in illegal activity (e.g., theft, fraud, unauthorized access beyond what is necessary for research), OliveOps reserves all rights and remedies.

15. Researcher Recognition

OliveOps may publicly recognize security researchers who responsibly disclose vulnerabilities. Recognition may include:

  • Inclusion in a "Hall of Fame" or credits list on our website
  • Attribution in security advisories
  • Public acknowledgment of your contribution

You may request anonymity or decline recognition. OliveOps will respect your preference.

16. Out-of-Scope Findings

The following are generally out of scope for this policy and do not require a vulnerability report:

  • Vulnerabilities in third-party services or libraries (report to the third-party provider)
  • Vulnerabilities in outdated or deprecated components
  • Missing security headers (unless they pose a significant risk)
  • Information disclosure that does not pose a security risk
  • Features working as designed (not bugs or vulnerabilities)
  • Social engineering or phishing vulnerabilities
  • Staff directory information or public organizational details

If you are unsure whether a finding is in scope, please contact support@oliveops.ca for clarification.

Report a vulnerability

Please send vulnerability reports to: support@oliveops.ca

Questions about this policy?

Contact us with any concerns or questions about this policy.