Trust center
Security research program
Effective date: July 28, 2026
Program status (honest)
OwnSig runs a responsible disclosure program today. We acknowledge valid reports, triage them through our incident process, and credit researchers who help us fix issues before public disclosure.
We do not currently operate a paid bug-bounty platform (no HackerOne/Bugcrowd bounties, no guaranteed cash rewards). If we launch formal bounties, this page and security.txt will be updated first.
How to report
Email security@ownsig.com or use Contact → security. Include reproduction steps, affected URLs, and impact. We aim to acknowledge within 2 business days.
Full rules, out-of-scope items, and coordinated disclosure timelines are in our disclosure & incident response policy.
In scope
- ownsig.com and customer-facing subdomains we operate (app, edge, status)
- OwnSig web application, API (
/api/v1/*), and tracking edge (/t/,/o/,/a/) - Authentication, authorisation, tenant isolation, and cryptography implementations
Recognition
With your permission we may thank you in release notes or a security-advisory post. Enterprise customers may request a letter confirming a good-faith report under this policy.