Responsible disclosure
If you believe you have found a security vulnerability in a system operated by OpsSolo, please send a concise report to support@opssolo.com.
Describe the affected OpsSolo URL or feature, the potential impact and the steps needed to reproduce the issue. Include only the minimum evidence needed to explain the report. Do not send passwords, payment-card data, authentication tokens or other people’s personal information.
This contact route is for reports about the public OpsSolo website and application features that OpsSolo operates. Do not access, change, copy or delete data belonging to another person. Do not disrupt the service, use social engineering, or conduct denial-of-service testing. Stop testing if you encounter private or customer data and report what happened without collecting more.
Payment, authentication, storage, email and hosting providers operate parts of the wider service under their own security policies. This page does not authorize testing their infrastructure or other customers’ accounts. Report concerns about a provider’s systems through that provider’s own security contact.
OpsSolo will review reports sent to this address. There is currently no published response-time commitment, bounty programme or blanket authorization for security testing. Do not assume that sending a report grants permission for further testing or creates legal protection. If you need clarification about scope, ask before testing.
This page explains OpsSolo’s current reporting route and boundaries. It is not a certification or a promise of legal immunity.