Report a vulnerability privately
Include the affected path, impact, safe reproduction steps, and any suggested mitigation. Do not include unnecessary personal data.
Current security boundaries
Remote fetch controls
Checker requests require public HTTPS targets, reject local and private addresses, revalidate redirects, and enforce time and size limits.
Restricted SVG
The validator rejects scripts, animation, external references, entities, embedded raster images, and interactive elements.
Local sensitive tools
Original logo artwork and pasted email headers remain in the browser and are not sent to OpenBIMI.
Minimal state
The anonymous alpha has no user accounts, domain claims, persistent reports, or stored customer assets.
Safe-harbour expectations
- Use only accounts, files, and domains you own or have explicit permission to test.
- Do not access, retain, alter, or disclose another person’s data.
- Do not degrade service, run denial-of-service tests, spam endpoints, or test third-party infrastructure through OpenBIMI.
- Stop when you confirm a vulnerability; do not pivot or establish persistence.
- Allow reasonable time for investigation and remediation before coordinated disclosure.
Useful report details
A concise report should identify the affected component and version, the preconditions, exact low-impact reproduction steps, observed versus expected behaviour, security impact, and any logs or screenshots that do not expose unrelated data.
Not security vulnerabilities
Provider refusal to display a logo, DNS propagation delays, mail reputation outcomes, missing certificates, and ordinary validation disagreements are usually product or standards issues. Report those in the public issue tracker after removing sensitive material.