Obsidian Peaks
Rent

Security and responsible disclosure

How to report a vulnerability, and how we handle it.

  • Draft — under review
  • Last updated 23 Sep 2026

Reporting

Found a weakness in obsidianpeaks.com, the Console, or the way we run the boxes? Write to security@obsidianpeaks.com. Tell us what you found, where, how to reproduce it, and how to reach you.

What we do

  • We acknowledge your report within three working days.
  • We keep you informed while we fix it, and tell you when it is done.
  • We do not take legal action against research done in good faith within these rules.
  • There is no bug bounty. We do not pay for reports.

Rules

  • Test only against your own account and instances. Never touch other customers’ data; if you reach it by accident, stop and report.
  • No denial of service, no spam, no social engineering of our staff or customers, no physical attacks.
  • Do not run scans or exploits against the platform from a rented instance beyond what a proof of concept needs; the acceptable use rules otherwise forbid probing the platform.
  • Give us reasonable time to fix before you publish.

How we run things

  • Sign-in to instances is by SSH key only.
  • Hardware you rent is not shared with another customer during your term.
  • Instance disks are deleted at teardown, and that teardown is verified.
  • Our operations key is used only for the reasons in section 7 of the customer terms, and every use is logged.
  • Card data is held by Stripe; we never see full card numbers.

Scope

In scope: obsidianpeaks.com, client.obsidianpeaks.com, and the instances and boxes we operate. Out of scope: the services of our sub-processors (Stripe, Cloudflare, Hetzner, Google, Resend), which have their own programmes.