Trust CenterReport a vulnerability, responsibly

Responsible Disclosure

We welcome good-faith security research. If you find a vulnerability, tell us before disclosing it publicly.

Last updated · 22 July 2026

Scope

The OnyxOne web platform and its services. Denial-of-service, social engineering and physical attacks are out of scope.

How to report

Email a clear, reproducible report to hello@onyxone.uk. Give us reasonable time to remediate before any public disclosure. We do not pursue legal action against good-faith researchers who follow this policy.

Recognition

We recognise valid reports and will acknowledge researchers who help us keep the platform secure.