KNOWLEDGE BASERESPONSIBLE DISCLOSURE POLICY

This document was last updated on January 1st, 2026.


We consider the security of our systems and especially customer data a top priority. But no matter how much effort we put into system security, the possibility of vulnerabilities arising is ever present.

If you happen to discover such a vulnerability, we would like to know about it so we can take steps to address it as quickly as possible. Doing so will help us better protect our clients and our systems.

We do not accept automatically generated reports of ANY kind, be it automated "security checks" or LLM outputs. Nor do we accept the insane barrage of reports about "Insecure TLS cipher enabled" mostly originating from Indian spammers. If you got to this page by Googling "disclosure" "the reward will be", you will be banned from my mailserver forever.

Please take the following steps if you find a vulnerability:

In turn, we promise the following:

We strive to resolve all problems as quickly as possible, and would like to play an active role in the ultimate publication on the problem (if applicable) after it is resolved.

If you have any further inquiries or questions regarding this policy, please do not hesitate to send an e-mail to security@osk.sh. Please note that emails not about security or this policy (including marketing mail) will be ignored.