OkamiSec

Legal

Vulnerability Disclosure & Testing Policy

Last updated 24 August 2026.

Reporting a vulnerability

If you find a security issue on okamisec.dev, email hello@okamisec.dev with what you found, how to reproduce it, and its potential impact. We aim to acknowledge genuine reports within a few business days.

Please don't publicly disclose an issue before we've had a reasonable chance to fix it.

Safe harbour

We won't pursue legal action against good-faith security research that follows this policy — testing okamisec.dev itself, not accessing, modifying or exfiltrating data beyond what's needed to demonstrate the issue, and reporting it to us before disclosing it elsewhere.

Scope

This policy covers okamisec.dev only. For issues in third-party services we use — such as Vercel (hosting) or Resend (email delivery) — please report those directly to the provider.

How OkamiSec tests client systems

The same principle applies in reverse when we're the ones testing:

  • We only test what's explicitly agreed in writing before work begins.
  • We don't perform intrusive or destructive testing without separate, written authorisation.
  • If we find something outside the agreed scope, we stop and tell you rather than continuing.
  • Findings and evidence are shared with you directly, not with anyone else, unless you ask us to.

Changes to this policy

If this policy changes materially, we'll update this page. This is an informational summary of our practice, not a substitute for legal advice.