Security & vulnerability disclosure
We take the security of Outage Observer seriously and welcome good-faith reports of potential vulnerabilities.
Reporting a vulnerability
Email hi@duskresearch.com, or open a private report via the repository's Security tab ("Report a vulnerability"). Please include steps to reproduce and any relevant logs or proof-of-concept.
What to expect
We aim to acknowledge reports within three business days, keep you informed as we investigate and ship a fix, and credit you once an issue is resolved if you'd like.
Scope
In scope: the Outage Observer Worker and its endpoints (outage.observer), the Slack, Discord, and Telegram bots, and the source repository. Out of scope: the upstream providers we monitor; our hosting provider (Cloudflare, report to them directly); denial-of-service testing; and social engineering.
Safe harbor
We will not pursue or support legal action against researchers who act in good faith, avoid privacy violations and service disruption, and give us a reasonable chance to remediate before any public disclosure.