Responsible disclosure
Security reports
If you find a security issue that may affect Open Space users or data, report it privately through the security address. Do not open a public Issue or disclose it on social media.
We usually acknowledge a report within 7 days, but cannot currently promise a fixed remediation deadline.
01
Supported scope
Security maintenance applies to the latest public version. Older versions may not receive a separate fix, so first confirm whether the issue still occurs in the latest version.
02
What a report should include
Include the version, platform, potential impact, reproduction steps, minimum necessary evidence, and any known mitigation. Do not submit real user data, passwords, access keys, or material beyond what is needed to demonstrate the issue.
03
Confidentiality and testing boundaries
Do not publish technical details until we have confirmed the issue and had reasonable time to address it. Avoid destructive testing, accessing data that is not yours, or actions that affect other users or services.
04
What happens next
We will confirm the report's scope, assess risk, and share progress where possible. Security reports are kept for no more than 3 years after resolution for review and prevention of similar issues.
Report a security issue
The subject is prefilled. Include only the minimum information needed in the message.