Security policy
Last updated: 25 August 2026
This is osky's vulnerability disclosure policy. It explains how to tell us about a security issue you've found on this site, what you can expect from us in return, and the ground rules for safe, good-faith research. If you've found a problem, please report it here first rather than on social media - it gives us a real chance to fix it before it's public.
osky is a small, pre-launch team, so please read the timings below as a genuine best-effort commitment rather than a guaranteed service level.
Scope
In scope:
- the public website at osky.uk, including the buyer, seller, investor and ideas pages and forms; and
- the API at api.osky.uk that powers those forms.
Out of scope:
- the underlying infrastructure of our providers, including Cloudflare's own platform, network or Turnstile service - please report those directly to Cloudflare;
- automated scanning, load testing, or anything that could degrade the service for other people, including denial-of-service (DoS) testing;
- social engineering of osky's team, contractors or website visitors;
- physical security - we don't have offices or hardware to test yet;
- third-party sites we merely link to, such as our social media profiles; and
- issues with no real-world security impact (for example, missing "best practice" headers or minor version disclosure) unless you can show how they could be exploited.
How to report
Email [email protected] with:
- a description of the issue and where you found it;
- steps to reproduce it;
- what you think the impact could be; and
- how we can reach you if we have follow-up questions.
You can also find this contact in machine-readable form at /.well-known/security.txt, per RFC 9116.
Please report privately and give us a reasonable chance to investigate and fix an issue before disclosing it publicly or to anyone else.
What to expect
The following is a proposal to give you a sense of what to expect, not an established service-level agreement:
- we aim to acknowledge your report within 5 working days;
- where we can, we'll let you know whether we consider it a genuine security issue and roughly how we plan to handle it;
- we'll try to keep you updated as we work on a fix, though timing will depend on severity and our capacity as a small team; and
- once it's resolved, we're happy to credit you in any public note about the fix, if you'd like.
Safe harbour
If you make a good-faith effort to find and report a vulnerability in line with this policy, we will not pursue legal action against you for that research, and we consider it authorised. This safe harbour applies as long as you:
- avoid privacy violations, degrading the service, and destroying or corrupting data;
- only interact with accounts and data you own, or that you have explicit permission to test;
- stop and report immediately if you encounter personal data that isn't yours, rather than continuing to explore it; and
- give us a reasonable opportunity to investigate and address an issue before any public disclosure.
If a third party brings a claim against you for research that falls within this policy, we will make it clear that your actions were conducted in compliance with it.
About this policy
osky is currently a small, pre-launch team, so response and fix times are best-effort rather than guaranteed. We'll do our best to keep you updated throughout. This policy is a starting point and may evolve as osky grows; we'll update the "last updated" date above when it changes.
Questions about this policy: [email protected]. See also our privacy notice and terms of use.