Security & Responsible Disclosure
OhMyLore takes security seriously. If you believe you have found a security vulnerability in our service, we ask that you disclose it to us privately so we can fix it before it is publicly known.
Reporting a vulnerability
Please email support@ohmylore.app
with the subject prefix [SECURITY]. Include:
- A clear description of the issue and its impact.
- Steps to reproduce, or a proof-of-concept request/payload if possible.
- Your contact details for follow-up (optional).
We will acknowledge your report within 5 business days and provide an initial assessment within 14 business days. For confirmed critical issues, we aim to ship a fix within 90 days.
Scope
The following are in scope for responsible disclosure:
ohmylore.app(the production application).-
The Cloud Run service that powers OhMyLore (any
*.run.appURL serving an OhMyLore response). - The Firebase project
ohmylore.
The following are out of scope:
- Third-party services we depend on (Firebase, Google Cloud, etc.). Please report directly to those providers.
- Issues requiring a compromised end-user device or browser extension.
- Social engineering of OhMyLore staff.
- Denial-of-service attacks (please do not test these against the live service).
Safe harbor
We will not pursue legal action against researchers who:
- Make a good-faith effort to comply with this policy.
- Avoid privacy violations, destruction of data, or interruption of service.
- Give us reasonable time to investigate and remediate before disclosing publicly.
Recognition
OhMyLore is currently a small hobby project and we do not yet offer monetary bounties. We are happy to credit researchers in a hall-of-fame section on this page for valid reports (with your permission). A formal bug-bounty program may be introduced post-launch.
Out-of-band contact
If support@ohmylore.app is unreachable, you may reach the
operator on the public Discord server (link on the
OhMyLore homepage).
Last updated: