Security
Reporting
Report vulnerabilities privately to security@oesalabs.com before any public disclosure. This covers both websites, the live services, and all projects, including software whose source has not published. Reports about pre-release software are explicitly welcome: coordinated disclosure does not wait for a repository to be public.
What to include
- What you found and where.
- Steps to reproduce, or enough detail to follow your reasoning.
- Impact as you understand it.
Expectations
Best effort from a small studio, honestly stated: acknowledgement normally within a few days, a straight answer about whether and when a fix ships, and credit if you want it. No bounty programme. Please avoid disruptive testing against live services.
Machine-readable contact
/.well-known/security.txt on this domain and on oesalabs.com.
Per-project policies
SwiftSync and Pika Suite maintain written security policies in their repositories, which publish with them. Until then, the address above is the single door for everything.