Trust center
Vulnerability disclosure & incident response
Effective date: July 18, 2026
1. Responsible disclosure
We welcome good-faith reports of security vulnerabilities in OwnSig products and infrastructure. Please email security@ownsig.com (or use Contact → security).
- We acknowledge reports within 2 business days.
- Provide steps to reproduce, affected URLs/endpoints, and impact. Do not access data that is not yours, disrupt service, or social-engineer customers or staff.
- We will not pursue civil or criminal claims against researchers who comply with this policy and applicable law.
- Public disclosure of a specific vulnerability should wait until we confirm a fix or mutually agree a timeline (typically 90 days).
2. Out of scope
- Denial-of-service, volumetric flooding, or spam against production.
- Physical attacks, phishing of OwnSig employees, or malware submission.
- Findings limited to missing best-practice headers without demonstrable impact.
- Issues in Customer-controlled IdPs, mail tenants, or third-party apps Customer connects.
3. Incident response (customers)
OwnSig maintains a documented incident response process (severity matrix, on-call, status page updates, post-mortem). For personal-data breaches affecting Customer Personal Data, we notify the affected Customer without undue delay and within 72 hours where feasible, consistent with the DPA.
Operational status and historical incidents are published at /status.