Help Center

Security Disclosure Policy

How to report a security vulnerability in Onsen, and what we will do about it.

Our commitment

Onsen holds deeply personal information, and we would rather hear about a problem from you than from an attacker. If you have found a security vulnerability, we want to know, and we will not take legal action against you for telling us in good faith under this policy.

How to report

Email security@onsenapp.com. Please include:

  • What you found and where (URL, endpoint, app version, platform)
  • How to reproduce it
  • What an attacker could achieve
  • Any proof-of-concept, screenshots or logs

What we will do

What we doWhen
Acknowledge your reportWithin 3 business days
Give you an initial assessmentWithin 10 business days
Keep you updatedAt least every 14 days until resolution
Tell you when it is fixedAlways
Credit youWith your permission, on this page

In scope

  • The Onsen mobile applications (iOS and Android, public store builds)
  • api.onsenapp.com and the Onsen API
  • www.onsenapp.com
  • assets.prod.onsenapp.com
  • community.onsenapp.com — our community forum. It runs Discourse, but we host and operate it ourselves, so anything wrong with it is ours to fix. Vulnerabilities in upstream Discourse itself are best reported to Discourse; a misconfiguration or a flaw in our deployment is ours

Out of scope

  • Third-party services (OpenAI, OneSignal, AWS, Amplitude, Sentry) — report to the vendor
  • Findings that require a jailbroken, rooted or otherwise compromised device, or runtime instrumentation such as Frida, unless you can show impact on a normal device
  • Social engineering of our people or users
  • Denial of service, volumetric testing, or anything that degrades service for real users
  • Missing security headers, cookie flags or TLS configuration with no demonstrated exploit
  • Reports produced solely by an automated scanner with no analysis

Rules

Please do: test only against your own account; stop as soon as you have confirmed the issue; give us reasonable time to fix it before disclosing publicly.

Please do not: access, modify or delete another person's data; exfiltrate data; degrade the service; or publish before we have had a chance to fix it.

If you follow this policy, we will treat your research as authorised, will not pursue legal action, and will work with you if a third party does.

Rewards

We do not currently run a paid bug bounty. We offer public credit and our genuine thanks, and we will say so plainly rather than imply a reward that does not exist.

Safe harbour

Research conducted in accordance with this policy is authorised under the Computer Misuse Act 1990 so far as it is within our power to authorise it. If legal action is brought against you by a third party for activity that complied with this policy, we will make that compliance known.