Skip to content
ORBITRAONE

Responsible disclosure

Report privately. Disclose together.

If you believe you have found a security vulnerability in ORBITRA ONE™ — on this website or in Orbitra Prime, Orbitra L1 or Orbitra Realm components — report it to us privately. We work with researchers to confirm the issue, fix it and agree how it is disclosed.

Reporting process

What a useful report contains.

Send reports through the form on this page or to hello@orbitraone.com. Clear, minimal reports are the quickest to confirm.

  1. 01

    The component

    The URL, interface, contract, client release or specification section affected, and its version if you know it.

  2. 02

    The impact

    What an attacker could achieve — read data, move assets, change state, bypass a limit — and under which conditions.

  3. 03

    The reproduction

    Minimal steps to reproduce the issue with your own accounts and test data, plus an inert proof of concept where one helps.

  4. 04

    Your contact

    How to reach you with follow-up questions, and whether you would like to be acknowledged when the issue is disclosed.

Testing guidance

Test without harming anyone.

01

Only your own accounts

Test only against accounts, keys and data that you own or are explicitly permitted to use. Stop once you can demonstrate the issue.

02

No exploit payloads against production

Never run or include exploit payloads that target production systems. Describe the mechanism and keep any proof of concept harmless.

03

No personal data

Do not access, copy, modify or retain other people’s data. If you encounter it, stop, and describe what you saw without including the data in your report.

04

No disruption

Do not degrade service for anyone else. Denial-of-service, spam, social engineering and physical intrusion are outside acceptable testing.

Scope

What the policy covers.

When you are unsure whether a finding is in scope, report it and ask.

In scope

  • orbitraone.com, its localized pages, forms and endpoints
  • Access-intake and inquiry flows, including consent handling
  • NexusSDK client libraries and documentation code samples
  • Orbitra L1 protocol specifications and node client releases
  • NexusWASM sandbox isolation and EVM Capsule gateway controls
  • Cryptographic implementations, including Q-Switch signature suites

Out of scope

  • Denial-of-service and volumetric attacks
  • Social engineering, phishing and physical attacks against people or premises
  • Automated scanner output without a demonstrated impact
  • Missing headers or best-practice suggestions without an exploitable issue
  • Findings that require the victim’s compromised device or unlocked account
  • Services operated by third parties — report these to their operators
  • Brand impersonation and scam sites — report these through the contact page

Response stages

What happens after you report.

  1. 01

    Acknowledge

    We confirm that your report has arrived and give you a reference for all further correspondence.

  2. 02

    Triage

    We reproduce the issue, assess its severity and the components affected, and share our assessment with you.

  3. 03

    Remediate

    We develop, test and release a fix, prioritized by severity, and keep you informed while the work continues.

  4. 04

    Coordinate disclosure

    We agree the timing and content of any public disclosure with you and, with your consent, acknowledge your contribution.

Remediating a complex issue can take longer than confirming it. Please keep the details confidential until disclosure has been agreed.

Safe harbor

Good-faith research under this policy is authorized.

If you follow the scope and rules above, avoid harm to people, data and service availability, and report promptly and confidentially, we treat your research as authorized and will not pursue legal action against you for it. If you are unsure whether an activity is permitted, ask before you test: write to hello@orbitraone.com.

Submit a report

Send your report to the security team.

Use this form or write to hello@orbitraone.com. Describe the issue, and never attach exploit payloads aimed at production systems or any personal data.

  1. 01Your report is acknowledged with a reference.
  2. 02Triage findings are shared once the issue is reproduced.
  3. 03Disclosure timing is agreed with you before anything is published.
  4. 04Never include passwords, private keys or other people’s data.

Never include passwords, private keys, seed phrases or identity documents.