security · disclosure

Vulnerability
disclosure

A safe-harbour policy for security researchers. How to report, what is in scope, and how fast we respond.

Safe harbour for good-faith research

How to report

Email [email protected] with the subject line [SECURITY]. Include the affected surface, reproduction steps, and the impact you observed.

reporting a sensitive issue

We acknowledge every report and triage within 24 hours. If you need to send sensitive details, an encryption key is available on request — just ask in your first email.

Scope

  • Production gateway at api.omegahq.dev
  • Marketing site at omegahq.dev
  • The packaged IDE installer and its update channel

Out of scope

  • Vulnerabilities in upstream Microsoft VS Code (report those to MSRC)
  • Vulnerabilities in third-party VS Code extensions
  • Social engineering of the founder or users

Response times

We triage a reported vulnerability within 24 hours and aim to ship a fix for anything critical within 30 days. We keep you updated as we work, and offer public credit unless you'd rather we didn't.

Safe harbour

Good-faith security research that follows this policy will not result in legal action. Don't exfiltrate user data, don't degrade service for others, and give us reasonable time to fix an issue before disclosing it publicly.