SECURITY / PRIVATE REPORTING
Report vulnerabilities privately.
Suspected vulnerabilities in OpenLegalCore code, this website or related public infrastructure should not be posted to public issues. Use the private channel below.
- Channel
- PRIVATE EMAIL
- Public issues
- DO NOT USE
- Disclosure
- COORDINATED
- Security guarantee
- NONE
PROJECT-WIDE PRIVATE CHANNEL
Send the first report directly.
Use the subject “OpenLegalCore security report”. Begin with a concise description; do not send credentials, private legal material or third-party confidential data.
01 WHAT BELONGS HERE
Suspected technical vulnerabilities.
Report a weakness that may affect OpenLegalCore code, this website, a public project service or related project-controlled infrastructure. This includes paths that may expose data, credentials, access controls or the integrity of public artefacts.
02 CHOOSE THE PRECISE CHANNEL
Use component reporting when it exists.
For Legal OCR Pipeline, GitHub Private Vulnerability Reporting and its versioned security policy remain the most precise first route. The project email is the fallback for cross-project, website or unclear reports.
03 WHAT TO INCLUDE
Enough detail to investigate safely.
Name the affected asset and version, the observed behaviour, reproducible steps and the likely impact. Include only evidence that can be shared safely and a contact path for clarification. A complete exploit is not required for the first report.
04 WHAT NOT TO SEND
Describe sensitive material; do not attach it.
Do not send personal or legal documents, credentials, tokens, private keys, production datasets or third-party confidential data. If such material may be involved, describe its category and wait for instructions for a suitable exchange.
05 WHAT HAPPENS NEXT
Private triage before public disclosure.
The report is reviewed privately, clarification is requested when needed and any disclosure is coordinated after a safe fix or mitigation is available. The project does not publish a response-time promise or operate a bug bounty.
06 EXPLICIT BOUNDARY
Reporting guidance is not testing permission.
Do not disrupt services, use social engineering, access third-party data, establish persistence or exfiltrate information. This page does not grant permission to test any system or alter any legal or contractual boundary.
ROUTING / THREE DISTINCT PURPOSES
Send each matter to the right public boundary.
PRODUCT / CONTRIBUTION
Use the affected public component repository for ordinary bugs and feature work.
Choose a public repository hello@openlegalcore.orgPARTNERSHIP / COMMERCIAL
Use the partnership channel for pilots, integrations and scoped adaptations.
sales@openlegalcore.orgSECURITY / PRIVATE
Use the monitored private channel for suspected technical vulnerabilities.
security@openlegalcore.org