Verified intake
A monitored address on an official domain and, where appropriate, a published encryption method.
OFFICEAVO is preparing a formal vulnerability-disclosure process. Until a verified reporting address and response commitment are published, do not send exploit details, credentials or personal data through unverified channels.
Protect people
Minimize data
Preserve evidence
Verify the channel
Current guidance
If you believe you have found a security issue, avoid accessing data that is not yours, changing or deleting records, degrading a service, using social engineering, or expanding testing beyond the minimum needed to understand the issue.
Keep a concise record of the affected surface, reproducible steps, observed impact and the time of observation. Do not publish sensitive details before a verified reporting route and coordinated process are available.
What the formal policy still needs to establish
A monitored address on an official domain and, where appropriate, a published encryption method.
Clear in-scope systems, excluded testing and handling rules for third-party services.
Acknowledgement, triage, remediation and disclosure expectations that the team can actually meet.
Reviewed safe-harbor language and boundaries, published only after appropriate legal and security review.
Product direction and current availability are kept separate.
A verified public reporting address has not been published. Monitor this page for the official channel and do not send sensitive material to guessed or unverified addresses.
No bug-bounty program, reward or eligibility terms are claimed.
Explore the public product overview or join the email-only readiness list.