Security
Report problems responsibly.
If you believe OnTap has a security vulnerability, use the security contact form. Do not include live secrets, private keys, personal data, or destructive proof-of-concept payloads.
Helpful details
- Affected URL or Tool
- Expected and observed behavior
- Minimal reproduction steps
- Likely impact
- Any non-destructive evidence
Research boundaries
Do not access other people’s data, degrade availability, perform social engineering, publish a vulnerability before it can be reviewed, or use testing to violate law. OnTap does not currently offer a bug bounty or guaranteed response timeframe.
Submit a security concern