Security

Vulnerability reporting

A coordinated path for reporting suspected security issues. Do not include personal, production or secret data in the first message.

01

Report privately

Email security@opliora.ee with affected version, impact, reproducible steps and a safe contact method.

02

Safe evidence

Use redacted screenshots or synthetic records. Never send customer databases, passwords, API keys or employee information.

03

Acknowledgement

We target acknowledgement within two business days and will establish a secure follow-up channel when needed.

04

Assessment

We reproduce, classify impact, identify affected releases and agree communication with impacted customers.

05

Remediation

Fixes follow controlled release and customer validation processes, with mitigations supplied when a release cannot be immediate.

06

Publication

Coordinated disclosure timing is agreed case by case. Service commitments apply only under the signed support agreement.