Responsible Disclosure Starts With a Clear Contact.
If you believe you have identified a security issue affecting the Omnitechnicus website or an Omnitechnicus-controlled system, use the guidance below to report it responsibly.
Effective September 2026
Reporting a Security Issue
Send suspected vulnerability reports to support@omnitechnicus.com with the subject Security Vulnerability Report. Please provide enough technical detail for the issue to be reproduced and evaluated without including unnecessary sensitive information.
What to Include
When practical, include the affected URL, hostname, application, or system; a concise description of the issue; steps needed to reproduce the behavior; the security impact you believe is possible; and sanitized screenshots, logs, or proof-of-concept details that help explain the finding.
Responsible Testing Boundaries
Please do not access, modify, retain, or disclose data that does not belong to you; degrade or interrupt services; perform destructive testing; conduct social engineering or credential attacks; run high-volume automated scanning; or test customer, partner, vendor, or other third-party systems without explicit written authorization from the system owner.
Authorization & Scope
Publishing this page or a security.txt file does not grant authorization to perform penetration testing, vulnerability scanning, exploitation, or any other intrusive activity against Omnitechnicus, its customers, or third parties. Authorized security assessments are governed by separate written scope and rules of engagement.
Response & Coordination
Omnitechnicus will make reasonable efforts to review legitimate reports, request clarification when necessary, and coordinate remediation or disclosure where appropriate. This page does not establish a bug-bounty program, promise compensation, or guarantee a specific response or remediation timeframe.
Machine-Readable Security Contact
Automated tools and security researchers can retrieve the RFC 9116 security contact file at /.well-known/security.txt. That endpoint is intentionally plain text because it is designed primarily for machine discovery.
Existing Client Support
For an active support request, suspected compromise, service outage, or operational issue in an existing client environment, use the Support page rather than the vulnerability-disclosure channel above.
