Responsible disclosure

Report security issues privately.

We appreciate good-faith security research. Please use the private SourcingOS contact channel so suspected vulnerabilities can be investigated before public disclosure.

How to report

Use the contact form and identify the request as a security report. Include the affected URL or feature, a concise description, reproduction steps, and the security impact you observed.

Open the private contact channel

Please do

Please do not

security.txt

SourcingOS also publishes a machine-readable security contact file for researchers and automated discovery.

View security.txt

Scope and safe-harbor note

This page describes the intended good-faith reporting process; it is not a blanket authorization for testing that violates law, third-party terms, privacy, availability, or other users' rights. When in doubt, report the concern without attempting further exploitation.