We welcome help from the research community in keeping Orvoq and our customers safe. If you believe you've found a security vulnerability in Orvoq, please report it to us privately so we can investigate and fix it before it's disclosed publicly.
We confirm we've received your report and it's in our queue.
Our severity rating and next steps, communicated directly to you.
For the duration of the investigation and remediation โ you won't be left wondering where things stand.
Once the issue is fixed and disclosed, we maintain a hall-of-fame acknowledgments list for researchers who report in good faith.
We will not pursue legal action against researchers who make a good-faith effort to comply with this policy.
To keep testing safe for everyone:
Only test against accounts and data you own or have explicit permission to test with. Don't access, modify, or exfiltrate another customer's data โ including through a demonstrated cross-tenant vulnerability. Stop at proof of concept.
Don't run automated scanners at a volume that could degrade service for other customers.
Give us a reasonable window to investigate and remediate before any public disclosure. We'll be transparent with you about progress and timeline if we need more.
Don't access, download, or retain more data than necessary to demonstrate the issue, and delete anything you did access once the report is filed.
We evaluate every report on its merits and will always err on the side of working with a researcher who reported in good faith, even where the letter of these rules wasn't followed perfectly.
We don't currently run a paid bug bounty program. Researchers who report a valid, previously-unknown vulnerability are credited (with permission) in our acknowledgments list and are welcome to note the finding on their own portfolio once it's fixed and disclosed.