Security

Reporting a security problem

If you have found a security weakness in Ottom, write to [email protected] with the word Security in the subject. A person reads every report. This page says what to send, what we do with it, and what we ask of you while we fix it.

What to send

Please do not send us anybody else’s personal data, even as proof. A screenshot of your own account or test data is enough.

What we promise

We do not run a paid bug bounty.

What we ask of you

Out of scope

For tools

The same contact is published in machine-readable form at /.well-known/security.txt, following RFC 9116.