OpenTrade developers take security very seriously. As such, we'd like to know when a security bug is found so that it can be fixed and disclosed as quickly as possible. Please report security bugs to our team. 1) Contact The OpenTrade team can be contacted by email at ivanivanovkzv@gmail.com. As it is with any bug, the more information provided the easier it will be to diagnose and fix. Any exploit code is very helpful and will not be released without consent from the reporter unless it has already been made public. 2) Disclosure The goal of the OpenTrade team is to work with the bug submitter to bug resolution as well as disclosure. We prefer to fully disclose the bug as soon as possible. It is reasonable to delay disclosure when the bug or the fix is not yet fully understood, the solution is not well-tested or for vendor coordination. However, we expect these delays to be short, measurable in days, not weeks or months. A disclosure date is negotiated by the security team working with the bug submitter as well as vendors. However, the OpenTrade team holds the final say when setting a disclosure date. The timeframe for disclosure is from immediate (esp. if it's already publicly known) to a few weeks. As a basic default policy, we expect report date to disclosure date to be on the order of 7 days. 3) Non-disclosure agreements The OpenTrade team is not a formal body and therefore unable to enter any non-disclosure agreements.