Odysec

Vulnerability Disclosure Policy

Last updated: July 30, 2026

Courtesy translation. This English text is provided for reference only. The authoritative version of this Policy is the Traditional Chinese version; in the event of any discrepancy, the Chinese version prevails.

Odysec welcomes good-faith security research. If you find a security issue in our systems or published tools, please report it under this policy — we take every report seriously and handle it through coordinated disclosure.

1. Scope

Out of scope: our customers' systems and assets (we cannot authorize you to test them), and third-party services (such as Cloudflare or payment providers).

2. How to report

Write to security@odysec.org, including where possible:

We do not currently run a bug bounty program; with your consent, we are glad to credit you by name once the issue is fixed.

3. What we do with reports

4. Boundaries of good-faith research

We will not pursue legal action against researchers who act in good faith within these boundaries:

Reminder. Conduct beyond these boundaries — for example, unauthorized testing of other parties' hosts or domains — may constitute unauthorized computer intrusion under Article 358 of the Taiwan Criminal Code or other legal liability, and is not protected by this policy.

5. Our own research conduct

As a security service provider, our outbound testing follows the same standard:

6. Contact

Security reports: security@odysec.org. The machine-readable version of this policy lives at /.well-known/security.txt, which is signed with the key below.

7. OpenPGP key

Use the following key to encrypt a report, or to verify the signature on our security.txt:

Fingerprint1795 7894 C857 54E0 C79D B366 BDBA 5F86 E344 9C97
IdentityOdysec <security@odysec.org>
Public key/pgp-key.txt

The key is also published in our Web Key Directory:

gpg --locate-external-keys security@odysec.org
curl -s https://odysec.org/.well-known/security.txt | gpg --verify
Verify against the fingerprint printed on this page, character by character. This page and the key file are served by the same host; if you have concerns about that host itself, please confirm the fingerprint with us through another channel.