If you believe you have found a security vulnerability in the Osprey extension, the osprey.ac website, or the api.osprey.ac proxy service, email us at support@osprey.ac.
Please do not report security vulnerabilities through public GitHub issues, discussions, or pull requests.
Include as much of the following as you can:
- A description of the issue and its potential impact
- Steps to reproduce it
- Any affected URLs, versions, or configuration
We will acknowledge your report as soon as we can, keep you informed as we investigate, and credit you in the fix if you would like.
This policy covers the Osprey browser extension, the osprey.ac website, and the api.osprey.ac proxy service. Vulnerabilities in third-party threat intelligence providers should be reported to those providers directly.
Our machine-readable disclosure details are published at https://osprey.ac/.well-known/security.txt.