01: Security

Security Disclosure

Reporting a vulnerability. Email security@onyxingenuity.com. Please include enough detail to reproduce the issue: the affected URL or component, the steps you took, and what you observed.

What we commit to. We acknowledge reports within five business days and tell you what we intend to do about the issue. If a report is valid and we fix it, we will tell you when the fix is live. If we decide not to act, we will say so and explain why rather than leaving the report unanswered.

Scope. This address covers the Onyx Ingenuity website at onyxingenuity.com and its subdomains. It does not cover NYRDAN™, which is in active development and is not publicly deployed; there is no production product surface to test.

Out of scope. Denial-of-service and volumetric testing, social engineering of our people or vendors, physical access attempts, and findings that require access to an account you do not control. Reports produced solely by an automated scanner, without a demonstrated impact, will be acknowledged but generally not actioned.

What we ask. Give us a reasonable opportunity to remediate before publishing. Do not access, modify, or retain data that is not yours. We do not currently operate a paid bug bounty, and we will not represent otherwise.