Over 100 ethical hackers protect OXware in production. Public scope, clear rules, fast triage. Median time-to-bounty is 7 days. We've paid out $42,300 to date.
Test against your own self-hosted OXware install. Do not test against oxware.top SaaS endpoints unless you have written permission.
app.py, blueprints, REST API, runbook executor, federation, CSI, KubeVirt, GitOps modules.oxware/frontend/templates/*, plugin SDK, validators.Two channels. Pick whichever fits. Both reach the security team within 1 business hour.
Preferred. Encrypted via the GitHub channel. Auto-creates a CVE pre-publication draft we can both edit.
Open a private advisoryFor non-GitHub users. Encrypt with our PGP key (fingerprint published in SECURITY.md).
root@oxware.topResearchers who responsibly disclosed validated vulnerabilities. Listed with consent. Thank you.
OXware will not pursue legal action against researchers who follow the rules in this page. We treat good-faith research as authorized testing.
Read full SECURITY.md