ProductAtlas In development
ExploreCreate a blueprintHow it worksDocs
Sign in

Legal ProductAtlas

Vulnerability Disclosure Policy

How to report security issues in ProductAtlas systems operated by opsAI LLC. This is not a bug bounty.

Effective
13 August 2026

Contents

  1. Contact
  2. Scope
  3. Out of scope
  4. How to report
  5. Coordinated disclosure

1Contact

Report security vulnerabilities in ProductAtlas by email to [email protected]. We prefer English.

Problems with published Blueprint or Release content, including harmful or policy-breaking listings, are not security reports. Use the report action on the Release or email [email protected] under the Acceptable Use Policy.

2Scope

This policy covers security vulnerabilities in ProductAtlas systems that opsAI LLC operates, including:

  • https://productatlas.app and staging.productatlas.app (web, API, and MCP surfaces).
  • admin.productatlas.app and staging-admin.productatlas.app.
  • Authentication, authorization, session handling, uploads, and other ProductAtlas application behavior we control.

Identity provider issues that belong to BeyondAuth itself, rather than to how ProductAtlas integrates with it, are outside this policy.

3Out of scope

The following are outside coordinated vulnerability disclosure under this policy:

  • Denial-of-service, volumetric, or resource-exhaustion testing.
  • Social engineering, phishing, or physical access to people, offices, or devices.
  • Spam, unverified scanner output without a demonstrated impact, or reports that only state a missing best-practice banner.
  • Accessing, modifying, or deleting data beyond the minimum needed to demonstrate a finding.
  • Testing against third-party services, publisher content, or systems we do not operate.

4How to report

Include enough detail for us to reproduce and assess the issue:

  • A clear description of the vulnerability and its potential impact.
  • The affected URL, host, API or MCP surface, and software or release version when known.
  • Step-by-step reproduction, including request or response samples where useful.
  • Any proof-of-concept limited to demonstrating the issue.

Do not include secrets, credentials, or personal data beyond what is needed to explain the finding. Prefer redacted evidence when full payloads would expose other people's data.

5Coordinated disclosure

Please give us a reasonable opportunity to investigate and fix a valid, in-scope issue before you disclose it publicly. opsAI LLC will not pursue legal action against researchers who report in good faith, stay within the scope of this policy, avoid privacy harm and service disruption, and keep findings confidential until we have had that opportunity.

ProductAtlas does not operate a bug bounty. We do not promise payment, credit, or a fixed response time. We will acknowledge reports we can act on and may ask clarifying questions.

ProductAtlas is a public knowledge platform operated by opsAI LLC. See also the Terms and Conditions and Acceptable Use Policy.

ProductAtlasA map of what great products know.

Product

  • Explore
  • How it works
  • Docs

Service

  • Service status

Legal

  • Terms
  • Privacy
  • Acceptable use
  • Cookies
  • Subprocessors
  • Security

A product of opsAI LLC, makers of Toggly.