Security Disclosure Policy
How to report a security vulnerability in Onsen, and what we will do about it.
Our commitment
Onsen holds deeply personal information, and we would rather hear about a problem from you than from an attacker. If you have found a security vulnerability, we want to know, and we will not take legal action against you for telling us in good faith under this policy.
How to report
Email security@onsenapp.com. Please include:
- What you found and where (URL, endpoint, app version, platform)
- How to reproduce it
- What an attacker could achieve
- Any proof-of-concept, screenshots or logs
What we will do
| What we do | When |
|---|---|
| Acknowledge your report | Within 3 business days |
| Give you an initial assessment | Within 10 business days |
| Keep you updated | At least every 14 days until resolution |
| Tell you when it is fixed | Always |
| Credit you | With your permission, on this page |
In scope
- The Onsen mobile applications (iOS and Android, public store builds)
- api.onsenapp.com and the Onsen API
- www.onsenapp.com
- assets.prod.onsenapp.com
- community.onsenapp.com — our community forum. It runs Discourse, but we host and operate it ourselves, so anything wrong with it is ours to fix. Vulnerabilities in upstream Discourse itself are best reported to Discourse; a misconfiguration or a flaw in our deployment is ours
Out of scope
- Third-party services (OpenAI, OneSignal, AWS, Amplitude, Sentry) — report to the vendor
- Findings that require a jailbroken, rooted or otherwise compromised device, or runtime instrumentation such as Frida, unless you can show impact on a normal device
- Social engineering of our people or users
- Denial of service, volumetric testing, or anything that degrades service for real users
- Missing security headers, cookie flags or TLS configuration with no demonstrated exploit
- Reports produced solely by an automated scanner with no analysis
Rules
Please do: test only against your own account; stop as soon as you have confirmed the issue; give us reasonable time to fix it before disclosing publicly.
Please do not: access, modify or delete another person's data; exfiltrate data; degrade the service; or publish before we have had a chance to fix it.
If you follow this policy, we will treat your research as authorised, will not pursue legal action, and will work with you if a third party does.
Rewards
We do not currently run a paid bug bounty. We offer public credit and our genuine thanks, and we will say so plainly rather than imply a reward that does not exist.
Safe harbour
Research conducted in accordance with this policy is authorised under the Computer Misuse Act 1990 so far as it is within our power to authorise it. If legal action is brought against you by a third party for activity that complied with this policy, we will make that compliance known.