Reporting
Found a weakness in obsidianpeaks.com, the Console, or the way we run the boxes? Write to security@obsidianpeaks.com. Tell us what you found, where, how to reproduce it, and how to reach you.
What we do
- We acknowledge your report within three working days.
- We keep you informed while we fix it, and tell you when it is done.
- We do not take legal action against research done in good faith within these rules.
- There is no bug bounty. We do not pay for reports.
Rules
- Test only against your own account and instances. Never touch other customers’ data; if you reach it by accident, stop and report.
- No denial of service, no spam, no social engineering of our staff or customers, no physical attacks.
- Do not run scans or exploits against the platform from a rented instance beyond what a proof of concept needs; the acceptable use rules otherwise forbid probing the platform.
- Give us reasonable time to fix before you publish.
How we run things
- Sign-in to instances is by SSH key only.
- Hardware you rent is not shared with another customer during your term.
- Instance disks are deleted at teardown, and that teardown is verified.
- Our operations key is used only for the reasons in section 7 of the customer terms, and every use is logged.
- Card data is held by Stripe; we never see full card numbers.
Scope
In scope: obsidianpeaks.com, client.obsidianpeaks.com, and the instances and boxes we operate. Out of scope: the services of our sub-processors (Stripe, Cloudflare, Hetzner, Google, Resend), which have their own programmes.
