generated: '2026-07-31' method: searched probe: true source: https://o9solutions.com/security/vulnerability-disclosure-policy policy: - https://o9solutions.com/security/vulnerability-disclosure-policy contact: - security@o9solutions.com program: name: Responsible Vulnerability Disclosure (RVD) Policy bug_bounty: false bug_bounty_note: >- o9 states explicitly that the program "isn't intended to represent a public bug bounty program" and that it does not offer rewards or compensation for submitting potential issues. No HackerOne / Bugcrowd / Intigriti listing was found. safe_harbor: false safe_harbor_note: >- o9 does NOT authorize security research against its systems. The policy prohibits unauthorized testing, exploitation, social engineering, physical attacks and denial-of-service without explicit authorization, and warns that unauthorized activity may result in legal action. This is a report-intake policy, not a research-permission policy. scope: - web applications - APIs - network infrastructure - mobile applications - any system, computer, application or service owned by o9 Solutions response_targets: acknowledgement: within 15 business days initial_assessment: within 10 business days resolution: >- no fixed SLA; confirmed vulnerabilities are handled as incidents under the o9 Cybersecurity Incident Response Plan, with periodic progress updates coordinated_disclosure: >- o9 requests that reporters do not publicly disclose until o9 has addressed the issue and confirmed closure; o9 may issue a security advisory afterward. last_updated: '2025-11-04' last_updated_note: 'page states: Last Update 04/11/2025 (DD/MM/YYYY)' security_txt: published: false note: /.well-known/security.txt returns 403 (WAF) on o9solutions.com and 404 on guide.o9solutions.com and documents.o9solutions.com — no RFC 9116 file is served. evidence: - source: https://o9solutions.com/security/vulnerability-disclosure-policy kind: disclosure page http_status: 200 keywords: - responsible vulnerability disclosure - report a vulnerability - security@o9solutions.com - source: https://o9solutions.com/security kind: security overview page linking the policy http_status: 200 x-evidence: fetched: '2026-07-31' contact_encoding: email addresses on both pages are Cloudflare email-protected; decoded to security@o9solutions.com