Vulnerability Disclosure Policy
OpenSourcePatents LLC (OSP) — Last updated: August 12, 2026
Our commitment
OSP builds open-source civic and security tools, and we believe security improves when researchers have a safe, clear way to report problems. If you’ve found a vulnerability in one of our systems, we want to hear about it, and we commit to working with you in good faith.
Safe harbor
We will not pursue or support legal action against anyone who discovers and reports a vulnerability in good faith and in accordance with this policy. We consider security research conducted under this policy to be authorized, lawful, and helpful. If a third party brings legal action against you for activity that complied with this policy, we will make it known that your actions were authorized.
This protection applies only so long as you follow the rules below.
Scope
In scope:
- opensourceforall.com and its subdomains
- opensourcepatents.us
- Public OSP repositories on GitHub
Out of scope:
- Third-party services OSP uses but does not operate (e.g. our hosting provider, payment processors)
- Physical attacks, social engineering, or phishing against OSP staff or users
- Denial-of-service (DoS/DDoS) or any volumetric/stress testing
- Automated scanning that degrades service for other users
If you’re unsure whether something is in scope, ask us first at the contact address below.
Rules
To stay protected under the safe harbor above, you agree to:
- Only test systems listed as in scope.
- Stop as soon as you’ve confirmed a vulnerability, and do not access, modify, or download data beyond the minimum needed to demonstrate it.
- Never exfiltrate, retain, or share data belonging to OSP or its users. If you encounter personal data, stop and report it immediately.
- Not degrade, disrupt, or damage our systems or the experience of other users.
- Give us a reasonable chance to fix the issue before disclosing it publicly.
- Comply with all applicable laws.
How to report
Email opensourcepatents@gmail.com with:
- Where you found it (URL, endpoint, or repository)
- Steps to reproduce it
- What an attacker could do with it
- Any supporting proof (screenshots, requests, logs)
Please send reports in English.
What to expect from us
- We’ll acknowledge your report within 5 business days.
- We’ll give you an initial assessment and keep you updated as we work on a fix.
- We’ll let you know when the issue is resolved.
- With your permission, we’re glad to credit you publicly for the find.
No monetary rewards (for now)
OSP is a small company and does not currently offer paid bounties. We deeply appreciate good-faith reports and will recognize your contribution publicly if you’d like. This may change as we grow.