1. How to report
Email security@openrevenue.com with a short summary, expected impact, and steps to reproduce. Attach proof-of-concept details only as needed to demonstrate the issue.
Do not open a public GitHub issue or post publicly about a vulnerability until we have confirmed and had a reasonable chance to remediate.
If GitHub private vulnerability reporting is enabled for our repository, you may use that channel instead of email.
2. What is in scope
- The OpenRevenue web application and marketing site (openrevenue.com and related subdomains).
- The tracker script and event ingestion APIs.
- The hosted MCP endpoint and related authentication.
- Account, billing, and first-party integration flows we operate.
3. What is out of scope
- Customer websites that embed the OpenRevenue tracker (report those to the site owner).
- Third-party services without a clear OpenRevenue impact.
- Social engineering, phishing, physical attacks, spam, or denial-of-service testing.
- Findings that rely only on outdated browsers, rooted devices, or unrealistic user behavior.
4. Response
We aim to acknowledge reports within 2 business days. After triage we will share next steps and an expected timeline when we can.
We may ask clarifying questions. Please keep the discussion confidential until we agree on disclosure.
5. Safe harbor
We will not pursue legal action against good-faith security research that avoids privacy violations, data destruction, and service disruption; does not access or modify data beyond what is needed to demonstrate the issue; and gives us a reasonable chance to remediate before public disclosure.
6. Machine-readable policy
A security.txt file is published at https://www.openrevenue.com/.well-known/security.txt for automated discovery.
For general product or privacy questions, write to support@openrevenue.com. Security reports should go to security@openrevenue.com.