Skip to content
Draft — pending legal reviewVersion 1.0 · Last updated 29 September 2026

Responsible disclosure

How to report a security vulnerability to us safely.

Legal documents are published in English. Text in [brackets] is a placeholder to be completed before launch.

Questions? Contact us

Reporting a vulnerability#

Email security@oxonia.app with a description, steps to reproduce and the affected URL. We will acknowledge within three working days and keep you updated until the issue is resolved.

Please#

  • Test only against your own accounts or our demo environment.
  • Do not access, change or delete other people’s data, and stop and tell us if you encounter it.
  • Do not run denial-of-service, spam or social-engineering tests.
  • Give us reasonable time to fix the issue before any public disclosure.

Safe harbour#

If you act in good faith and follow this policy, we will not pursue legal action against you for your research, and we will credit you if you wish.