Site security
Report a vulnerability without disrupting the service.
If you believe you found a vulnerability, help us address it without exposing others or disrupting the service.
How to report
See `/.well-known/security.txt` for the current security address and terms. Do not place vulnerability details in the general form.
Describe the component, likely impact and a non-destructive reproduction path. Encrypt the message if a published key allows it.
Mutual expectations
Do
Limit access to what is strictly necessary, stop if real data appears and allow a reasonable correction period.
Avoid
Denial of service, social engineering, persistence, exfiltration, physical access or tests against third parties.
Response
Optigm targets acknowledgement within the published business-day window, without promising a bounty or universal deadline.
Site architecture
Static content sits behind CloudFront and a private bucket. The form uses a limited API and Lambda, no database, with SES delivery.
Security headers, throttling, privacy-preserving logs and alarms are managed as code and checked before deployment.
Technical channel
Report without using the general form.
Email security@optigm.com. Start with a summary without sensitive data; current terms remain in security.txt.
Next step
For commercial requests, use the general contact.
For a vulnerability, only use the channel in security.txt.