Security
Vulnerability Disclosure
Last updated: August 21, 2026
We take the security of Open Tag seriously. If you believe you've found a security vulnerability, we appreciate your help in disclosing it to us responsibly.
How to report
Email security@opentag.bot with the details. Please do not disclose the issue publicly until we've had a chance to investigate and address it.
What to include
- A clear description of the vulnerability and its impact.
- Step-by-step instructions to reproduce it.
- Any proof-of-concept code, logs, or screenshots.
- The affected version, URL, or component.
- How we can reach you for follow-up.
Our commitment
- We'll acknowledge your report within 3 business days.
- We'll keep you informed as we investigate and work toward a fix.
- We'll credit you for the discovery if you'd like, once the issue is resolved.
Safe harbor
We will not pursue or support legal action against researchers who, in good faith, discover and report vulnerabilities in accordance with this policy. This means you should avoid privacy violations, data destruction, and service degradation, and only interact with accounts you own or have permission to test.
Scope
This policy covers the Open Tag hosted service and our related repositories. Vulnerabilities in third-party model providers or tools you connect should be reported to those vendors directly; see our Subprocessors page.
Please avoid
- Accessing or modifying data that isn't yours.
- Denial-of-service testing or automated scanning at scale.
- Social engineering, phishing, or physical attacks.
Contact
Security team: security@opentag.bot. Thank you for helping keep Open Tag and its users safe.