If you discover a security vulnerability in the Orgs platform, in any of our SDKs, in the registered-agent pipeline, or in any system-related infrastructure, we want to hear from you.

Contact

Email: security@orgs.sh PGP: Our key on keys.openpgp.org Fingerprint: 4F8A 7B19 C3D2 ... E7F6 C2D6

What we commit to

  • Acknowledgment within 24 hours
  • Initial triage within 72 hours
  • Status updates at least weekly until resolved
  • Public disclosure 90 days after report OR upon patch, whichever is sooner
  • Credit in our security acknowledgments (opt-in)
  • Bounty per the scale below, via our Security Research Program

Bounty scale

SeverityExampleBounty
CriticalAuthentication bypass, key extraction, PII leak at scale10,00010,000 – 25,000
HighPrivilege escalation, audit-chain manipulation, unauthorized disbursement2,5002,500 – 10,000
MediumLogic flaws with limited exploitation, info disclosure500500 – 2,500
LowUI issues, outdated dependencies with no known exploitHall of Fame mention

Scope

In scope:
  • orgs.sh website and console
  • api.orgs.sh endpoints
  • Published SDKs (Rust, TypeScript, Python, Go, Swift, Kotlin)
  • MCP server binaries
  • Our hosted registered-agent pipeline
  • Audit chain verification logic
Out of scope:
  • Third-party services we integrate with (Mercury, Relay, Meow, Anthropic, etc.)
  • Vulnerabilities in underlying protocols (Solana, Sigil, Ethereum)
  • Social engineering of Orgs employees
  • Denial of service / volumetric attacks
  • Clickjacking on non-auth-critical pages

Safe harbor

We offer safe harbor for good-faith security research:
  1. Do not intentionally harm the confidentiality, integrity, or availability of data
  2. Do not modify, copy, or exfiltrate data not your own
  3. Do not violate any applicable law
  4. Give us a reasonable time to respond before public disclosure
If you follow these, we will not pursue legal action and will actively defend you against third-party claims arising from your research in scope.

Hall of Fame

Researchers who’ve helped us over the past year:
  •  Q2 2026: @example1 — SSRF in registered-agent pipeline, severity HIGH
  •  Q1 2026: @example2 — auth-bypass via JWT misconfiguration, severity CRITICAL
Opt out of listing: note in your report.