๐Ÿ›ก๏ธSentinelOSS

Reporting a security issue

Last updated: September 2026

How to report

Email [email protected]. Please include what you found, where, the steps to reproduce it, and what an attacker could do with it. Screenshots or a short proof of concept help. Please don't post the details publicly until we have had a chance to fix it.

What is in scope

  • sentineloss.cloudrf.xyz โ€” the SentinelOSS web app and its API
  • ta.cloudrf.xyz โ€” TrustAuthority
  • tap.cloudrf.xyz โ€” TAP, the agent firewall

Not in scope: reports that only list missing best-practice headers without a working attack, denial of service, spam or social engineering, and issues in third-party services we use (report those to their owners).

What we ask

  • Test only against your own account and data. Never access, change or delete other people's data.
  • Don't degrade the service for others โ€” no load testing, flooding or automated mass scanning.
  • Stop and report as soon as you have shown the issue exists; don't go further than you need to.
  • Give us reasonable time to fix it before disclosing publicly โ€” normally up to 90 days.

What you can expect

  • A reply within 7 days confirming we received your report.
  • Updates while we investigate and fix it.
  • Credit when the fix ships, if you would like it.
  • We will not pursue or support legal action against anyone who reports in good faith and follows the rules on this page.

There is no paid bug bounty at the moment.

Disputing a finding about your package

If you maintain a package and think SentinelOSS or TrustAuthority got something wrong about it, that is not a security report โ€” use the dispute form.