Skip to content
OnboardUX
  • Solutions
  • Demo
  • How it works
  • For FDEs
  • Security
  • Resources
GitHubDesign partner
SolutionsDemoHow it worksFor FDEsSecurityResourcesGitHubDesign partner
  1. Home
  2. Legal
  3. Vulnerability disclosure

LEGAL & TRUST

Vulnerability disclosure

Draft reporting page. A secure channel, scope, safe-harbor terms, response expectations, and key have not been approved.

Status
Draft — do not rely on this page as a reporting channel
Last reviewed
2026-08-14
This development copy contains explicit business and legal placeholders. It must be reviewed by qualified counsel and completed before production launch.
There is no approved vulnerability-reporting channel yet. Do not send vulnerability details through the disabled general contact form.

Reporting channel

The monitored contact is[SECURITY DISCLOSURE CONTACT — REQUIRED BEFORE PRODUCTION]. A secure submission method and, if adopted, public encryption key remain[SECURE REPORTING METHOD — REQUIRED BEFORE PRODUCTION].

Scope and authorization

Testing scope, excluded systems, testing methods, coordinated-disclosure rules, and authorization language are [DISCLOSURE SCOPE AND RULES — REQUIRED BEFORE PRODUCTION]. This draft does not grant authorization to test any system and does not promise safe harbor.

What a future report should contain

Once a channel is approved, a useful report would normally include:

  • the affected URL or component and a concise description;
  • reproduction steps and observed impact;
  • non-sensitive supporting material; and
  • a preferred contact method, if a response is requested.

Do not include client data, credentials, secrets, or unnecessary personal data.

Response and disclosure

No acknowledgement time, remediation SLA, bounty, status-update cadence, credit, or public-disclosure timeline is promised. Approved expectations remain[SECURITY RESPONSE AND DISCLOSURE PROCESS — REQUIRED BEFORE PRODUCTION].

Machine-readable policy

The production `/.well-known/security.txt` must identify a usable contact and approved expiry date. Its current policy link does not replace those unresolved fields. See also the Securitypage for product and website control status.

OnboardUX

The post-implementation layer for custom software and AI systems.

[LEGAL ENTITY NAME — REQUIRED BEFORE PRODUCTION]

Product

  • Solutions
  • Demo
  • For FDEs
  • Delivery leaders
  • Plans

Developers

  • GitHub
  • Getting started
  • CLI status
  • Resources

Trust

  • Security
  • DPA
  • Subprocessors
  • Vulnerability disclosure
  • Accessibility

Legal

  • Privacy
  • Terms
  • Cookies
  • Acceptable use
  • Privacy choices
  • Company details
© 2026 Onboard UX. Draft website.No advertising trackers or non-essential storage.