Vulnerability Disclosure Policy
Effective September 15, 2026 | Last Updated September 15, 2026 | Version 1.0
Ollify LLC ("Ollify," "we," "us," or "our") takes the security of our platform and the privacy of our customers seriously. We believe that working with security researchers to identify and responsibly disclose vulnerabilities makes the internet safer for everyone.
This Vulnerability Disclosure Policy ("VDP") describes how to report security vulnerabilities in Ollify's systems to us, what we commit to in return, and the legal protections we extend to researchers acting in good faith. We encourage security researchers — whether experienced professionals, students, or anyone who has discovered something that looks wrong — to report concerns to us rather than leaving them unaddressed or disclosing them publicly before we have had a chance to fix them.
THIS IS JUST A DISCLOSURE POLICY
Ollify does not currently offer monetary compensation for vulnerability reports. We offer safe harbor protections, public acknowledgment (if desired), direct access to our engineering team, and our genuine gratitude. If Ollify introduces a paid bug bounty program in the future, this policy will be updated.
1. Scope
The following table describes what is and is not within scope for this VDP. Please review carefully before beginning any security research.
✓ IN SCOPE
| ✗ OUT OF SCOPE
|
IF YOU ARE UNSURE WHETHER SOMETHING IS IN SCOPE
When in doubt, email us at security@ollify.app and ask before testing. We would rather answer a scoping question than have a researcher inadvertently violate this policy. We will respond to scoping questions within 3 business days.
2. How to Report a Vulnerability
To report a vulnerability, send an email to security@ollify.app. We handle all security reports through this channel. Please do not report vulnerabilities through our general support or legal channels.
Contact: security@ollify.app
Subject line: "Security Vulnerability Report — [brief description]"
Response time: We acknowledge all reports within 3 business days.
Your report should include as much of the following as possible. More detail helps us reproduce and fix issues faster:
Description | A clear description of the vulnerability — what it is, where it exists, and what type of vulnerability it is (e.g., XSS, IDOR, SQL injection, authentication bypass). |
Reproduction Steps | Step-by-step instructions to reproduce the issue. Include URLs, parameters, request/response bodies, and any other details needed. The more specific, the faster we can validate. |
Proof of Concept | A demonstration of the vulnerability — screenshots, screen recordings, HTTP request/response captures, or a working PoC. We only ask that you demonstrate existence, not cause actual damage. |
Impact Assessment | Your assessment of the potential business or security impact. Who could be affected? What data could be accessed or modified? This helps us prioritize. |
Affected System | The specific URL, endpoint, API route, or application component where the vulnerability exists. |
Your Environment | Browser, OS, or tool version if relevant to reproduction. |
Suggested Fix | Optional but appreciated — your recommendation for remediation if you have one. |
2.1 Encryption. If your report contains particularly sensitive details — for example, proof of access to customer data — you may request PGP encryption by emailing security@ollify.app; a published public PGP key is not yet available. Unencrypted reports are also accepted and will be handled with the same care.
2.2 Anonymous Reports. You may submit a report anonymously. However, we will not be able to provide you with updates on remediation progress or reach out with questions if something in your report is unclear. If you wish to remain anonymous but still receive updates, consider using a pseudonymous email address.
3. What Ollify Commits To
We treat all good-faith security reports seriously and commit to the following:
Acknowledgment | We will acknowledge receipt of your report within 3 business days of receiving it. |
Validation | We will investigate and validate the reported vulnerability within 14 business days of acknowledgment. Complex issues may take longer — we will let you know. |
Regular Updates | We will keep you informed of our remediation progress at reasonable intervals, typically every 14 days, until the issue is resolved. |
Fix Notification | We will notify you when the vulnerability has been fixed and the fix has been deployed. |
Public Credit | If you would like public recognition, we will keep a private record of your contribution for future public credit; a public Security Hall of Fame page is planned but not yet published. If you prefer to remain anonymous, we will not disclose your identity. |
No Legal Action | We will not pursue or recommend civil or criminal legal action against you for research conducted in good faith in accordance with this VDP. See Section 4. |
Honest Communication | If we disagree with your assessment of a vulnerability's severity or exploitability, we will explain our reasoning. We will not dismiss valid reports without explanation. |
4. Safe Harbor
SAFE HARBOR
Ollify will not initiate or recommend legal action against any security researcher who reports vulnerabilities to us in good faith in accordance with this policy. We consider good-faith security research to be authorized and beneficial activity and we want researchers to feel safe working with us.
This Safe Harbor is a clear waiver of any claims arising under the Computer Fraud and Abuse Act (18 U.S.C. § 1030), the Digital Millennium Copyright Act anti-circumvention provisions (17 U.S.C. § 1201), and analogous state computer crime statutes, for research conducted in accordance with this policy. We will not refer good-faith researchers to law enforcement.
4.1 Conditions for Safe Harbor Protection. Safe harbor protections apply when the researcher:
Reports the vulnerability to Ollify through the process described in Section 2 before any public disclosure.
Makes a good-faith effort to avoid privacy violations, data destruction, data exfiltration, and disruption of the Service to other users.
Limits testing to what is reasonably necessary to demonstrate the existence and impact of the vulnerability.
Does not access, modify, exfiltrate, or retain data beyond what is minimally necessary to demonstrate the vulnerability — and deletes any data accessed as part of testing.
Does not conduct testing that degrades the performance or availability of the Service for other users.
Does not publicly disclose the vulnerability before the earlier of: (a) 90 days from initial report; or (b) Ollify's deployment of a fix, as described in Section 5.
Does not extort or demand payment in exchange for not disclosing the vulnerability.
4.2 Conduct Not Covered by Safe Harbor. Safe harbor protections do not apply to:
- (a)
accessing, downloading, or exfiltrating production customer data beyond what is minimally necessary to demonstrate a vulnerability;
- (b)
intentionally destroying, modifying, or corrupting data;
- (c)
conducting DoS or DDoS attacks;
- (d)
exploiting a vulnerability beyond demonstrating its existence;
- (e)
demanding payment or threatening disclosure in exchange for not reporting;
- (f)
any activity that violates applicable law beyond what is strictly necessary to demonstrate a security vulnerability and that cannot be remediated by Ollify through good-faith engagement.
4.3 If You Are Uncertain. If you are unsure whether a specific testing action would fall within safe harbor protections, email security@ollify.app and ask before proceeding. We would rather clarify in advance than have a researcher inadvertently step outside the policy.
5. Coordinated Disclosure and Timing
We follow a coordinated disclosure model. This means we ask researchers to report privately and give us a reasonable opportunity to fix the issue before any public disclosure.
Day 0 — Report Received | Researcher submits vulnerability report to security@ollify.app. The 90-day private disclosure window begins. |
Days 1–3 | Ollify acknowledges receipt of the report and assigns it to the security team for investigation. |
Days 1–14 | Ollify validates the vulnerability and assesses severity. We will communicate our findings and a remediation timeline. |
Days 14–90 | Ollify remediates the vulnerability. We provide regular progress updates. Researchers are notified when a fix is deployed. |
Day 90 (Default) | If the vulnerability is not fixed by day 90, researchers may proceed with public disclosure at their discretion, subject to the coordinated disclosure process described below. |
After Fix | Researchers may publish details of the vulnerability at any time after Ollify's fix is deployed. We encourage coordinated disclosure — contact us to coordinate timing. |
5.1 If Remediation Takes Longer Than 90 Days. Some vulnerabilities — particularly complex architectural issues — take longer than 90 days to fully remediate. If we cannot fix a vulnerability within 90 days, we will:
- (a)
proactively reach out to the researcher to explain the delay and provide a revised timeline;
- (b)
share information about any interim mitigations we have put in place; and
- (c)
request a reasonable extension of the disclosure window.
We will not request extensions indefinitely. If the researcher and Ollify cannot agree on an extension, the researcher may proceed with public disclosure at day 90 in accordance with this policy.
5.2 Emergency Disclosure. If a vulnerability is being actively exploited in the wild before Ollify has had a reasonable opportunity to remediate, the researcher and Ollify may agree to a shorter disclosure timeline in the interest of public safety. Contact security@ollify.app to initiate emergency coordination.
5.3 Coordinating Publication. When you are ready to publish details of a resolved vulnerability, please let us know in advance so we can review for any remaining sensitive information and coordinate timing. We support and encourage publication — security research benefits the community and we want to help researchers get full credit for their work.
6. What We Do Not Offer
To set accurate expectations:
We do NOT offer
| We DO offer
|
7. This Policy Is Not For
This VDP is specifically for reporting security vulnerabilities. Please use the correct channel for other inquiries:
If you need to… | Use this channel | Contact |
Report a security vulnerability | This VDP | security@ollify.app |
Get customer support or report a bug | Support | support@ollify.app |
Report a privacy concern or exercise data rights | Privacy | privacy@ollify.app |
Report a copyright / DMCA issue | DMCA | legal@ollify.app |
Submit a legal notice or contract matter | Legal | legal@ollify.app |
Report a billing or payment issue | Billing | billing@ollify.app |
Report abuse or AUP violations | Abuse | abuse@ollify.app |
8. Contact
Security Reports | security@ollify.app |
This Policy URL | ollify.app/security/disclosure |
Mailing Address | Ollify LLC, 901 N State St. STE N, Jackson, MS 39202 |
Acknowledgment Time | Within 3 business days of receipt |
Validation Time | Within 14 business days of acknowledgment |