Responsible Disclosure Policy
Last updated July 31, 2026
In short. Found a security issue? Please tell us privately at team@orbitsub.com before disclosing it anywhere else, give us reasonable time to fix it, and don’t access other people’s data or disrupt the Service. Act in good faith and we’ll work with you gratefully — we won’t pursue action against good-faith researchers who follow this policy.
OrbitSub, operated by KARAN (“we”), values the security community. This Responsible Disclosure Policy explains how to report a vulnerability and the rules for doing so safely. It works with our Security Policy and Terms of Service.
1. How to report a vulnerability
Email team@orbitsub.com with the subject line starting “Security:”. To help us understand and fix the issue quickly, please include:
- a clear description of the vulnerability and its potential impact;
- step-by-step instructions to reproduce it;
- the affected URL, page, or component;
- any proof-of-concept, screenshots, or logs that help (without exposing real user data);
- how we can reach you for follow-up.
2. The rules (safe harbour)
We will treat security research conducted in good faith and in line with this policy as authorised, and we will not pursue or support legal action against you for it. In return, you agree to:
- report the issue to us privately and promptly, and not disclose it publicly until we’ve had reasonable time to fix it;
- not access, modify, or delete data that isn’t yours — use only your own test accounts;
- not degrade, disrupt, or overload the Service (no denial-of-service, no spam, no automated high-volume testing that harms availability);
- not use social engineering, phishing, or physical attacks against our users, staff, or providers;
- stop testing and contact us immediately if you encounter personal data, and not retain, copy, or share it;
- comply with all applicable laws.
Testing that goes beyond these rules is not authorised and is not covered by this policy.
3. In scope
Vulnerabilities on the OrbitSub Service — the website at orbitsub.com, its subdomains, and our application — are generally in scope, including issues such as authentication or authorisation flaws, injection, data exposure, and similar security bugs.
4. Out of scope
The following are generally not considered valid security issues:
- vulnerabilities in third-party services we use (report those to the relevant provider — e.g. PayPal, Vercel, Cloudflare);
- issues requiring physical access to a user’s device, or a already-compromised device;
- social-engineering or phishing of users or staff;
- denial-of-service, volumetric, or rate-limit testing;
- missing best-practice headers or configurations with no demonstrable security impact;
- reports from automated scanners without a demonstrated, exploitable issue.
5. What you can expect from us
- we will acknowledge your report, ordinarily within a few business days;
- we will investigate, keep you reasonably updated, and work to fix confirmed issues as quickly as we responsibly can;
- we will credit researchers who wish to be recognised, once an issue is resolved;
- we will act in good faith toward researchers who act in good faith.
6. Rewards
OrbitSub is an early-stage, independently run project, and we do not currently operate a paid bug bounty program. We may, entirely at our discretion, recognise especially valuable reports — for example with public credit or a token of thanks — but no monetary reward should be assumed. Please report issues because you want to help keep the community safe. If we introduce a formal rewards program in future, we’ll describe it here.
7. Changes and contact
We may update this Policy from time to time; the current version and the “Last updated” date are shown here. To report a security issue, email team@orbitsub.com.