Vulnerability disclosure policy

Last updated: 2026-05-24

Ollagraph welcomes reports from independent security researchers. This page describes what we consider in scope, how to report a vulnerability, what we promise in return, and what we ask researchers not to do.

Reporting a vulnerability

Email [email protected]. Include:

If you would like to encrypt your report, ask for our PGP key in your first message and we will reply with it.

In scope

Vulnerability classes we want to hear about, in roughly descending priority:

Out of scope

The following are known limitations or accepted trade-offs and are not eligible for reward or coordinated disclosure unless they enable an in-scope class above:

Safe harbour

If you make a good-faith effort to comply with this policy when investigating a vulnerability, Ollagraph will:

"Good-faith effort" means: you do not access or modify other customers' data beyond the minimum needed to demonstrate the issue; you do not exfiltrate data; you do not deliberately disrupt the service for other users; you report the issue promptly; and you give us a reasonable window to fix it before public disclosure.

What we promise in response

Target time to fix, by severity:

Coordinated disclosure

We ask researchers to keep the details private until either (a) the fix is deployed and verified, or (b) 90 days from initial report — whichever comes first. If the fix is not in production at the 90-day mark we will discuss an extension with you; we will not invoke the 90 days as a reason to stay silent past it.

Hall of fame

Researchers who have helped harden Ollagraph will be listed here once we receive our first qualifying report.

Contact

Security reports: [email protected]
General security questions: see the security page and the architecture page.