Ordnary

Technology

Responsible Disclosure Policy

Last updated July 24, 2026

Our responsible disclosure program: scope, recognition, and the process for reporting a vulnerability in more detail than our Security Policy covers.

Our Security Policy explains the basics of how to report a vulnerability and the safe harbor we offer researchers. This page sets out our responsible disclosure process in more detail: what's in scope, how reports are triaged, and how we recognize researchers who help us.

We don't currently run a paid bug bounty program. Valid reports are recognized on our Hall of Fame and, at our discretion, may be rewarded with Ordnary Web Services credit.

Scope

In scope for this program:

  • ordnary.com, guidelines.ordnary.com, and other production Ordnary web properties;
  • Ordnary Web Services infrastructure and APIs;
  • Ordnary account and authentication systems; and
  • publicly available Ordnary mobile and desktop applications.

Out of scope:

  • third-party services we integrate with but don't control, such as payment processors or infrastructure providers;
  • denial-of-service, spam, and social engineering against our staff or users;
  • physical security, and attacks requiring physical access to a device;
  • issues that require a jailbroken or rooted device, or an outdated browser, to exploit; and
  • automated scanner output without a demonstrated, working proof of concept.

Reporting process

Email security@ordnary.com with a description of the issue, steps to reproduce it, the affected component, and any proof-of-concept material. We aim to acknowledge new reports within 2 business days, and to give you an initial triage decision, meaning whether it's accepted, needs more information, or is out of scope, within 10 business days.

Once a report is accepted, we'll keep you updated as we investigate and remediate. We ask that you keep the details confidential until we confirm a fix is deployed, or for 90 days after your report, whichever comes first, unless we agree to a different timeline together.

Hall of Fame and Ordnary Web Services credit

We don't offer a paid bug bounty program at this time. For every valid, in-scope report, we're happy to add you to our Hall of Fame with your permission. At our discretion, based on the severity and quality of the report, we may also grant Ordnary Web Services credit as a thank-you. There's no fixed schedule or guaranteed amount; this is a discretionary way for us to say thanks, not a paid program.

The first researcher to report a given issue with enough detail to reproduce it is eligible for recognition and any credit we choose to grant. Duplicate reports aren't eligible, even if submitted independently around the same time.

Eligibility

To be eligible for recognition or Ordnary Web Services credit, you must follow this policy and the Security Policy, report the issue before disclosing it to anyone else, and not be a current or former Ordnary employee or contractor who had access to the relevant system.

Recognition

With your permission, we're happy to publicly credit researchers who report a valid issue on our Hall of Fame. Let us know in your report if you'd like to be credited, and how you'd like your name or handle to appear.

Safe harbor

This program is covered by the safe harbor described in our Security Policy: we won't pursue, or support, legal action against researchers who act in good faith, stay within this scope, and follow the reporting process above.

Changes to this program

We may adjust the scope, recognition, or process for this program at any time, including introducing a paid bug bounty program in the future. Changes apply to reports submitted after the change takes effect.

Contact

Vulnerability reports and responsible disclosure questions: security@ordnary.com.

For urgent requests, call +31 85 401 3197.