Ormaven

Security & Responsible Disclosure

If you believe you found a security weakness affecting ormaven.com or an Ormaven tool, please report it privately so it can be investigated before public disclosure.

How to report

Send a concise report to hello@ormaven.com with the subject “Security report”. Include the affected URL or component, observed behaviour, reproduction steps and potential impact. Do not include unnecessary personal data or secrets.

Good-faith research

Avoid accessing, changing, deleting or downloading data that is not yours; avoid denial-of-service, social engineering, spam, physical attacks and destructive testing. Stop testing if you encounter sensitive data and report the issue privately.

What to expect

Ormaven will acknowledge credible reports when reasonably possible, investigate proportionately to risk and aim to communicate material remediation. No bug-bounty programme or guaranteed response time is currently offered.

Public disclosure

Please allow a reasonable period for investigation and remediation before public disclosure. If a vulnerability affects a third-party provider, coordinated disclosure with that provider may be necessary.