Security

Report vulnerabilities privately so there is time to understand the issue, protect users, and coordinate a responsible fix.

Publisher status

Openly Useful is the public brand. Openly Useful LLC is the planned legal entity, with status formation-pending. This policy does not represent that planned entity as formed or active.

Report a vulnerability

Email hello@openlyuseful.org with subject SECURITY. Where a repository offers GitHub private vulnerability reporting, that private channel is preferred.

Include the affected domain, product, package, or repository; a clear description; reproduction steps or a proof of concept; the potential impact; and a safe way to contact you. Do not include secrets that are unrelated to the report.

Scope

Third-party services, customer systems, social engineering, denial-of-service activity, destructive testing, and infrastructure or accounts you do not own are out of scope. Use local reproduction and the least invasive proof possible.

What to expect

We will make a reasonable effort to acknowledge reports, provide progress updates when practical, and coordinate a disclosure timeline, but no guaranteed response time is offered. Please allow time to investigate and address the issue before publishing details. Credit will be offered when appropriate unless you prefer otherwise.

Good-faith research

Good-faith research means following this policy, avoiding privacy violations and service disruption, accessing only the minimum information needed to demonstrate an issue, and reporting promptly. This policy does not authorize activity prohibited by law or by a third party’s rules.

Effective and last updated August 16, 2026.