Skip to content
OpenReserve

Security and Responsible Disclosure

Effective 2026-10-07 · Last updated 2026-10-08

This page explains how we protect OpenReserve and the data in it, and how to report a security vulnerability.

In plain English: Found a security problem? Email security@openreserve.app. We will answer within 3 business days, we will not take legal action against good-faith research, and we will credit you if you like.

1. How we protect your data

  • Encryption. All connections use HTTPS (TLS). Data is encrypted at rest in our database, file storage and backups.
  • Separation between businesses. Every record that belongs to a business is tagged with it, and the database itself enforces that one business can never read another's data, in addition to the checks in our application.
  • Sign-in. Access tokens are short-lived and signed; sessions are stored on our servers so they can be revoked instantly; one-time sign-in codes expire quickly. Payment details are handled by Stripe and never reach our servers.
  • Least privilege. Our team's access to production systems is limited to the people and permissions they need, and is logged. Production and development run in separate cloud accounts.
  • Audit trail. Sensitive actions in each business account are recorded in an audit log.
  • Secrets. Keys and credentials are kept in a managed secret store, never in source code.
  • Backups. Database recovery history is configured for six hours. Tenant media storage does not keep object versions. This recovery-history setting does not specify when every backup copy held by a provider is physically erased.
  • Vendors. We use established providers (listed on our subprocessors page) under contracts that require them to protect data.

2. If something goes wrong

If we learn of a security incident that affects personal data, we investigate immediately, contain it, and notify affected businesses, people and authorities as the law requires. Under our Data Processing Addendum, we notify affected businesses without undue delay and within 72 hours of confirming a breach of their data.

3. Reporting a vulnerability

Email security@openreserve.app with:

  • What you found and where (the URL, app version or API endpoint).
  • Steps to reproduce it, and what an attacker could do with it.
  • Your name or handle if you would like to be credited.

We will acknowledge your report within 3 business days, keep you informed while we fix it, and tell you when it is fixed. Please give us a reasonable time to fix the issue before you disclose it publicly; we aim to fix serious issues within 90 days.

4. Safe harbor

We will not pursue legal action against you for security research that:

  • Is done in good faith, and only to find and report vulnerabilities.
  • Uses only accounts you own or have explicit permission to use.
  • Does not access, change or delete other people's data beyond the minimum needed to show the issue, and stops as soon as you encounter personal data.
  • Does not degrade the Service for others: no denial-of-service, spam or brute-force testing.
  • Is reported to us promptly and kept confidential until we have fixed it.

If in doubt about whether something is in scope, ask us first at security@openreserve.app.

5. Scope

In scope: openreserve.app and its subdomains, and the OpenReserve for Business and OpenReserve apps.

Out of scope: services run by other companies (for example Amazon Web Services, Stripe, Vercel, Expo, Cloudflare, Microsoft 365, and Neon; report issues to them directly), social engineering or phishing of our team or users, physical attacks, denial-of-service, and reports without a demonstrated security impact (such as missing best-practice headers or software version disclosure on their own).

6. Rewards

We do not run a paid bug bounty program, but we are grateful for every good-faith report and will gladly credit you.

A machine-readable version of this contact information is published at /.well-known/security.txt.