_

Vulnerability Disclosure Policy (VDP)

Responsible Disclosure Policy

Introduction

OPO Oeschger AG (OPO) recognizes the valuable contribution of security researchers, customers, partners and users who help us improve the security of our digital services.

If you discover a potential security vulnerability in any digital asset owned, operated or maintained by OPO Oeschger AG, we encourage you to report it responsibly using our Security Vulnerability Report Form.

This policy explains how to report security vulnerabilities to us and what you can expect from OPO during the handling of your report. We are committed to reviewing all legitimate security reports and working to address confirmed vulnerabilities in a timely manner.

Scope

 

This policy applies to publicly accessible digital assets owned, operated or maintained by OPO Oeschger AG.

Out of Scope

Please note that some parts of our systems and infrastructure are provided by third parties.

Vulnerabilities affecting third-party systems should be reported directly to the relevant provider whenever possible. Where appropriate, OPO may forward reports to the responsible third party; however, responsibility for remediation remains with the owner of the affected system.

Our Commitment

When reporting a vulnerability in accordance with this policy, you can expect OPO to:

  • Acknowledge receipt of your report in a timely manner.
  • Review, assess and validate the reported vulnerability.
  • Maintain an open and constructive dialogue regarding the reported issue.
  • Work to remediate confirmed vulnerabilities as appropriate.
  • Provide updates on the handling and progress of your report where possible.
  • Notify you when a reported vulnerability has been resolved.
  • Apply the Safe Harbor provisions described in this policy for research conducted in good faith.

Our Expectations for Responsible Disclosure

When reporting vulnerabilities, we ask you to:

  • Act in accordance with this policy and all applicable laws.
  • Report vulnerabilities as soon as reasonably possible after discovery.
  • Avoid exploiting vulnerabilities beyond what is necessary to demonstrate their existence.
  • Respect the privacy and confidentiality of our customers, partners and employees.
  • Avoid disrupting services, destroying data or negatively affecting user experience.
  • Use only the official reporting channel provided by OPO.
  • Keep information about discovered vulnerabilities confidential until remediation has been completed and disclosure has been coordinated with OPO.
  • If a vulnerability provides unintended access to data, access only the minimum amount of information required to demonstrate the issue and cease testing immediately thereafter.
  • Only interact with accounts and systems that you own or are explicitly authorized to test.
  • Refrain from any form of extortion, coercion or threats.
  • Provide OPO with a reasonable opportunity to investigate and resolve the reported issue before public disclosure.
  • Coordinate with OPO prior to publishing any information related to the vulnerability.

Prohibited Activities

While we encourage responsible reporting of security vulnerabilities, the following activities are strictly prohibited:

  • Actions that may negatively affect OPO, its customers, partners or systems, including phishing, spam, brute-force attacks, denial-of-service attacks or similar activities.

  • Destroying, modifying or accessing data that does not belong to you.
  • Physical or electronic attacks against OPO personnel, buildings, facilities or infrastructure.
  • Social engineering of OPO employees, customers, suppliers or contractors.
  • Installation of malware, backdoors or persistent access mechanisms.
  • Any activity that results in unauthorized disclosure of personal or confidential information.

No Rewards

OPO Oeschger AG appreciates responsible security disclosures. However, this process is not a bug bounty program and does not provide financial rewards, compensation or incentives for reported vulnerabilities.

Coordinated Vulnerability Disclosure (CVD)

OPO values the efforts of individuals who responsibly disclose security vulnerabilities and allows public disclosure under the following conditions:

  • The vulnerability is not publicly disclosed before OPO confirms that the issue has been resolved and agrees that publication is appropriate.
  • Public disclosure must not include exploit code, proof-of-concept code or technical details that could facilitate misuse of the vulnerability.

Reporting Security Vulnerabilities

Please report security vulnerabilities through our Security Vulnerability Report Form:

GO TO THE VDP REPORTING FORM

To help us investigate and resolve the issue efficiently, please provide as much information as possible, including:

  • A clear technical description of the vulnerability.
  • The affected URL(s), applications, systems or services.
  • Detailed steps required to reproduce the issue.
  • Browser, operating system and device information.
  • Screenshots, logs or proof-of-concept material where appropriate.
  • An assessment of the potential impact and risk.
  • Date and time of discovery.
  • Your contact details for follow-up questions.
  • Any intended disclosure plans.

Please note that this reporting channel is intended exclusively for undisclosed security vulnerabilities. General support requests, product inquiries, feature requests or other non-security-related matters may not receive a response through this channel.

Legal Safe Harbor

For security research conducted in good faith and in compliance with this policy:

  • OPO will not initiate civil legal action against individuals for accidental or unintentional violations of this policy.
  • Activities carried out in accordance with this policy will be considered authorized for the purpose of security testing of in-scope systems.
  • OPO will not pursue legal claims for legitimate research intended solely to identify and report security vulnerabilities.
  • If a third party initiates legal action related to activities conducted in compliance with this policy, OPO may make known that the actions were undertaken in accordance with this Responsible Disclosure Policy.
  • OPO reserves the right to take legal action in cases involving malicious intent, significant abuse, criminal activity or serious violations of this policy.

Researchers are expected at all times to comply with all applicable laws and regulations. If you are unsure whether your intended actions are consistent with this policy, please submit a report through the official reporting channel before continuing any testing activities.

Please note that this Safe Harbor applies only to legal claims under the control of OPO Oeschger AG and does not bind any independent third party.

Last updated: August 2026