Our full Vulnerability Disclosure Policy lives at attomus.com/security — read it first.
Quick reference for researchers landing here from GitHub:
- Report to:
security@attomus.com - Acknowledgement: within 48 hours.
- Initial assessment: within 7 days.
- Resolution target: 90 days from initial report.
- Disclosure embargo: 90 days minimum.
- PGP key: available on request from
security@attomus.com. - Safe harbour: yes, for good-faith research under the published policy.
- Bug bounty: none currently. Public acknowledgement on request.
Scope and out-of-scope are defined on the canonical page. If you are unsure whether something is in scope, report it anyway.