outage.observer Live board →

Security & vulnerability disclosure

We take the security of Outage Observer seriously and welcome good-faith reports of potential vulnerabilities.

Last updated 18 June 2026. Machine-readable contact: /.well-known/security.txt.

Reporting a vulnerability

Email hi@duskresearch.com, or open a private report via the repository's Security tab ("Report a vulnerability"). Please include steps to reproduce and any relevant logs or proof-of-concept.

What to expect

We aim to acknowledge reports within three business days, keep you informed as we investigate and ship a fix, and credit you once an issue is resolved if you'd like.

Scope

In scope: the Outage Observer Worker and its endpoints (outage.observer), the Slack, Discord, and Telegram bots, and the source repository. Out of scope: the upstream providers we monitor; our hosting provider (Cloudflare, report to them directly); denial-of-service testing; and social engineering.

Safe harbor

We will not pursue or support legal action against researchers who act in good faith, avoid privacy violations and service disruption, and give us a reasonable chance to remediate before any public disclosure.