Legal
Security Disclosure Policy
Last updated: August 2026
This page covers this public website only — the marketing and content surface at this domain. It does not describe the security posture of any product, platform, or service that has not yet reached general availability.
Reporting a vulnerability
A dedicated security reporting channel (for example, a monitored [email protected] address or a security.txt file) is not yet established for this website. Until a formal channel is published here, report a suspected vulnerability through the contact page and state clearly in your message that you are reporting a security issue.
What to include in a report
- A description of the vulnerability and the affected page, route, or endpoint.
- Steps to reproduce, including any request/response detail that helps confirm it.
- The potential impact as you understand it.
- Contact information so we can follow up or ask clarifying questions.
What not to do
- Do not access, modify, or exfiltrate data beyond what is needed to demonstrate the issue.
- Do not run automated scanning or load-testing against this website without prior authorization.
- Do not publicly disclose a suspected vulnerability before we have had a reasonable opportunity to review it.
Response commitment
We do not yet have a published response-time service level for security reports on this website. A formal response-time commitment is pending; we will update this page when one is adopted. This is a factual limitation, not a target we are choosing not to meet.
Safe harbor
We do not currently publish a formal safe-harbor commitment for good-faith security research against this website. If this is a concern for your research, say so in your report through the contact page and we will respond to that question directly rather than assume coverage that has not been documented here.
Scope
This policy applies to the public website at this domain. It does not extend authorization to test third-party services this site links to, or to any system not operated by Omnacta.
Changes to this policy
We will update the date at the top of this page when this policy changes materially, including when a monitored security contact or formal response-time commitment is adopted.