Site security

Report a vulnerability without disrupting the service.

If you believe you found a vulnerability, help us address it without exposing others or disrupting the service.

How to report

See `/.well-known/security.txt` for the current security address and terms. Do not place vulnerability details in the general form.

Describe the component, likely impact and a non-destructive reproduction path. Encrypt the message if a published key allows it.

Mutual expectations

  • Do

    Limit access to what is strictly necessary, stop if real data appears and allow a reasonable correction period.

  • Avoid

    Denial of service, social engineering, persistence, exfiltration, physical access or tests against third parties.

  • Response

    Optigm targets acknowledgement within the published business-day window, without promising a bounty or universal deadline.

Site architecture

Static content sits behind CloudFront and a private bucket. The form uses a limited API and Lambda, no database, with SES delivery.

Security headers, throttling, privacy-preserving logs and alarms are managed as code and checked before deployment.

Technical channel

Report without using the general form.

Email security@optigm.com. Start with a summary without sensitive data; current terms remain in security.txt.

Next step

For commercial requests, use the general contact.

For a vulnerability, only use the channel in security.txt.