Vulnerability Disclosure Policy

Effective date: April 30, 2026

This policy covers system-o.org and its subdomains. The site is operated by Press Pause Garage LLC, a Florida limited liability company, which welcomes reports from security researchers and treats all good-faith reports seriously.

Scope

In scope: system-o.org and any subdomain operated by this site, except where explicitly excluded.

Out of scope

How to report

Email: [email protected]

For sensitive details, encrypt your report using our PGP key:
https://system-o.org/.well-known/openpgpkey/security.asc

Please include:

What to expect

This site is operated by Press Pause Garage LLC, a solo operation. Response times are best-effort, not contractual:

We do not currently offer monetary bug bounties. We do offer public acknowledgment with your consent.

Coordinated disclosure

We follow a coordinated disclosure model. Please give us 90 days from initial report before public disclosure as a default. We are happy to negotiate this window in either direction based on severity, complexity, and exploitation evidence.

If we have not responded to a confirmed report within 30 days, you may escalate by re-sending with "ESCALATION" in the subject line.

Safe harbor

Press Pause Garage LLC will not pursue legal action against researchers who:

This safe harbor applies only to actions covered by this policy and does not authorize activity inconsistent with applicable law.

Updates

Last updated April 30, 2026. Material changes will be published here, and the Expires field on our security.txt will be refreshed annually.