# OIOXO — how to report a security issue # # security.txt is the first place a researcher looks (RFC 9116), and its absence # means a finding either goes unreported or goes public. This file exists so that # never happens for want of an address. # # The address is support@oioxo.com and NOT security@oioxo.com, deliberately: # support@ is the mailbox this product already routes and answers, while a # security@ alias that silently bounced would be worse than publishing nothing — # it would look like a disclosure path while swallowing reports. Contact: mailto:support@oioxo.com Expires: 2027-09-11T00:00:00.000Z Preferred-Languages: en Canonical: https://oioxo.com/.well-known/security.txt Policy: https://oioxo.com/security # What is most useful to us, in rough order: anything that lets one account read # or bill another; anything that extracts a user's API key or source code from # the browser; anything that lets a page outside oioxo.com drive the IDE. # # Please give us a reasonable window to fix before publishing, and do not test # against accounts that are not yours. We do not run a paid bounty today and will # say so plainly rather than imply one.