How to report
Email [email protected] with the subject line [SECURITY]. Include the affected surface, reproduction steps, and the impact you observed.
reporting a sensitive issue
We acknowledge every report and triage within 24 hours. If you need to send sensitive details, an encryption key is available on request — just ask in your first email.
Scope
- Production gateway at
api.omegahq.dev - Marketing site at
omegahq.dev - The packaged IDE installer and its update channel
Out of scope
- Vulnerabilities in upstream Microsoft VS Code (report those to MSRC)
- Vulnerabilities in third-party VS Code extensions
- Social engineering of the founder or users
Response times
We triage a reported vulnerability within 24 hours and aim to ship a fix for anything critical within 30 days. We keep you updated as we work, and offer public credit unless you'd rather we didn't.
Safe harbour
Good-faith security research that follows this policy will not result in legal action. Don't exfiltrate user data, don't degrade service for others, and give us reasonable time to fix an issue before disclosing it publicly.