Security

Vulnerability Disclosure

Last updated: August 21, 2026

We take the security of Open Tag seriously. If you believe you've found a security vulnerability, we appreciate your help in disclosing it to us responsibly.

How to report

Email security@opentag.bot with the details. Please do not disclose the issue publicly until we've had a chance to investigate and address it.

What to include

Our commitment

Safe harbor

We will not pursue or support legal action against researchers who, in good faith, discover and report vulnerabilities in accordance with this policy. This means you should avoid privacy violations, data destruction, and service degradation, and only interact with accounts you own or have permission to test.

Scope

This policy covers the Open Tag hosted service and our related repositories. Vulnerabilities in third-party model providers or tools you connect should be reported to those vendors directly; see our Subprocessors page.

Please avoid

Contact

Security team: security@opentag.bot. Thank you for helping keep Open Tag and its users safe.