Responsible Disclosure

Reporting a security vulnerability

We treat every security report as a gift. If you've found something in Outwright that could put customer data at risk, please tell us — we'll triage fast, fix it, credit you (if you'd like), and never threaten you for the disclosure.

Send your report to

Plain email is fine. Include a description, reproduction steps, and any proof-of-concept. We reply within 48 hours.

Scope

In scope

If a vulnerability you've found applies to any of these surfaces, we want to hear about it:

Out of scope

The following are not in scope and will not be acknowledged with a fix or recognition:

Safe harbor

Outwright will not pursue legal action against security researchers who:

This safe harbor is intended to encourage security research that benefits all Outwright customers. We aim to make these terms compatible with the EFF's vulnerability disclosure FAQ and the standard responsible-disclosure norms used by Stripe, Vercel, and Cloudflare.

Authorized testing only. If your testing requires more than a few requests against the production application, please ask first — we'd rather you have an isolated test environment than have anomaly-detection alarms paged in the middle of the night. Email us and we'll set you up.

What we commit to

When you submit a report in good faith, we commit to:

Stage
Commitment
Initial acknowledgment
Within 48 hours of receipt — confirming we got your report and assigning a tracking ID.
Triage & severity assessment
Within 7 days — we'll tell you what we think the severity is and our planned response.
Remediation (high / critical)
Within 30 days for confirmed high or critical issues. We'll keep you in the loop on progress.
Coordinated disclosure
After remediation, we'll work with you on a disclosure timeline that respects affected customers and your contributions.
Post-mortem (critical)
For confirmed critical issues, we publish a post-mortem to affected customers under NDA within 30 days of resolution.

If we can't meet a stated timeline, we'll tell you why and when we expect to be back on track.

Recognition

We'd like to acknowledge contributions from researchers who help keep our customers safe. If you submit a confirmed and remediated vulnerability and you'd like public credit, please tell us and we'll add you to the acknowledgments list below. If you'd prefer to stay anonymous, that's fine too — your call.

We are not currently running a paid bug bounty program. As we grow, we plan to add a structured bounty program (likely via HackerOne or Bugcrowd). Until then, recognition is the only formal benefit we can offer for confirmed reports.

Encrypted reports

For sensitive reports, an encrypted PGP channel is being set up; until the public key is published here, please send reports unencrypted to security@outwright.ai. Email between most enterprise providers is already TLS-encrypted in transit. If your report is unusually sensitive and you'd prefer to wait for PGP, email us and we'll coordinate.

Acknowledgments

Researchers who have responsibly disclosed verified vulnerabilities to Outwright will be listed here, with their consent.

No public acknowledgments yet — be the first.

Questions about this policy

If anything above is unclear or you'd like to discuss a specific test plan before running it, write to security@outwright.ai. For non-security questions, see our contact page.

This policy is published in machine-readable form at /.well-known/security.txt per RFC 9116. Last updated 2026-04-26.