Only your own accounts
Test only against accounts, keys and data that you own or are explicitly permitted to use. Stop once you can demonstrate the issue.
Responsible disclosure
If you believe you have found a security vulnerability in ORBITRA ONE™ — on this website or in Orbitra Prime, Orbitra L1 or Orbitra Realm components — report it to us privately. We work with researchers to confirm the issue, fix it and agree how it is disclosed.
Reporting process
Send reports through the form on this page or to hello@orbitraone.com. Clear, minimal reports are the quickest to confirm.
The URL, interface, contract, client release or specification section affected, and its version if you know it.
What an attacker could achieve — read data, move assets, change state, bypass a limit — and under which conditions.
Minimal steps to reproduce the issue with your own accounts and test data, plus an inert proof of concept where one helps.
How to reach you with follow-up questions, and whether you would like to be acknowledged when the issue is disclosed.
Testing guidance
Test only against accounts, keys and data that you own or are explicitly permitted to use. Stop once you can demonstrate the issue.
Never run or include exploit payloads that target production systems. Describe the mechanism and keep any proof of concept harmless.
Do not access, copy, modify or retain other people’s data. If you encounter it, stop, and describe what you saw without including the data in your report.
Do not degrade service for anyone else. Denial-of-service, spam, social engineering and physical intrusion are outside acceptable testing.
Scope
When you are unsure whether a finding is in scope, report it and ask.
In scope
Out of scope
Response stages
We confirm that your report has arrived and give you a reference for all further correspondence.
We reproduce the issue, assess its severity and the components affected, and share our assessment with you.
We develop, test and release a fix, prioritized by severity, and keep you informed while the work continues.
We agree the timing and content of any public disclosure with you and, with your consent, acknowledge your contribution.
Remediating a complex issue can take longer than confirming it. Please keep the details confidential until disclosure has been agreed.
Safe harbor
Good-faith research under this policy is authorized.
If you follow the scope and rules above, avoid harm to people, data and service availability, and report promptly and confidentially, we treat your research as authorized and will not pursue legal action against you for it. If you are unsure whether an activity is permitted, ask before you test: write to hello@orbitraone.com.
Submit a report
Use this form or write to hello@orbitraone.com. Describe the issue, and never attach exploit payloads aimed at production systems or any personal data.