SECURITY CONTACT

Report security issues directly.

Security requests and vulnerability reports are monitored by the SupraOS security team. SupraOS aims to acknowledge credible reports within two business days.

Effective and last reviewed: 16 July 2026

Security review requests

Email security@supraos.co. The mailbox is monitored by the SupraOS security team. Include your company, role, the proposed or current deployment, the material requested, your deadline, and whether an NDA is in place.

Vulnerability reports

Send the affected domain or component, a concise description, security impact, safe reproduction steps, date and time observed, sanitized screenshots or request IDs, and a safe contact method. Do not include customer data, passwords, access tokens, or sensitive exploit material in the first email.

In-scope systems

  • https://supraos.co
  • https://www.supraos.co
  • https://preview.supraos.co, including SupraOS-owned login and access pages
  • SupraOS-owned APIs and connector services explicitly identified by SupraOS or in a customer deployment

This policy does not authorize testing of a third-party service. A vulnerability in a third-party product must be reported under that provider’s policy.

Limited authorization for good-faith research

SupraOS authorizes good-faith testing of the in-scope SupraOS-owned systems above when you use accounts, workspaces, and data you own or have written permission to test, use the minimum proof required, and report the issue responsibly.

  • Stop if you encounter customer data, credentials, personal data, or another customer’s workspace.
  • Do not copy, retain, alter, or delete data that is not yours.
  • Do not perform denial-of-service, load, brute-force, spam, destructive, persistence, extortion, social-engineering, phishing, physical, or employee-targeting activity.
  • Do not disrupt production workflows or connector actions.
  • Do not test third-party systems without their permission.
  • Give SupraOS a reasonable opportunity to investigate and remediate before public disclosure.

Safe harbor

For research conducted within the limited authorization above, SupraOS will not pursue legal action solely for the authorized testing. This safe harbor does not apply to activity outside the authorization, including access to customer data, third-party testing, operational disruption, persistence, extortion, or unlawful conduct.

Response and disclosure

Acknowledgement

SupraOS aims to acknowledge a credible report within two business days. Further timing depends on severity, complexity, affected customers, and third-party coordination.

Coordinated disclosure

Please coordinate public disclosure so SupraOS can validate the issue, protect affected customers, and complete remediation. The timeline will be agreed for the specific report.

Recognition

A reporter may be credited, if requested, when the report leads to a confirmed fix.

No paid bounty

SupraOS does not currently operate a paid bug-bounty program. A report does not create a right to payment.

Urgent customer incident

Existing customers should use the incident contact in the order form or deployment schedule and copy security@supraos.co. Include the workspace, affected integration, observed time, and a safe callback number. Do not send secrets by email.