Security

Report quietly.
Fix openly.

Protecting visitors and third-party domains matters more than public proof. Please report suspected vulnerabilities privately before disclosure.

Last updated 2 August 2026

Report a vulnerability privately

Include the affected path, impact, safe reproduction steps, and any suggested mitigation. Do not include unnecessary personal data.

Open private report

Current security boundaries

Remote fetch controls

Checker requests require public HTTPS targets, reject local and private addresses, revalidate redirects, and enforce time and size limits.

Restricted SVG

The validator rejects scripts, animation, external references, entities, embedded raster images, and interactive elements.

Local sensitive tools

Original logo artwork and pasted email headers remain in the browser and are not sent to OpenBIMI.

Minimal state

The anonymous alpha has no user accounts, domain claims, persistent reports, or stored customer assets.

Safe-harbour expectations

  • Use only accounts, files, and domains you own or have explicit permission to test.
  • Do not access, retain, alter, or disclose another person’s data.
  • Do not degrade service, run denial-of-service tests, spam endpoints, or test third-party infrastructure through OpenBIMI.
  • Stop when you confirm a vulnerability; do not pivot or establish persistence.
  • Allow reasonable time for investigation and remediation before coordinated disclosure.

Useful report details

A concise report should identify the affected component and version, the preconditions, exact low-impact reproduction steps, observed versus expected behaviour, security impact, and any logs or screenshots that do not expose unrelated data.

Not security vulnerabilities

Provider refusal to display a logo, DNS propagation delays, mail reputation outcomes, missing certificates, and ordinary validation disagreements are usually product or standards issues. Report those in the public issue tracker after removing sensitive material.