Do not open a public issue for suspected vulnerabilities. Email pitechae@gmail.com with the subject OpenAPI Studio security report and include:
- The affected route, component, or commit
- Reproduction steps and expected impact
- Any suggested mitigation
Do not access data that is not yours, degrade the service, or include credentials, customer data, or confidential API contracts in the report. Receipt will be acknowledged within three business days. No bug-bounty program is currently offered.
Good-faith research that follows these boundaries will not be pursued or referred for legal action by the project owner.
Only the latest commit on main and the named Cloudflare preview are in scope. OpenAPI Studio is a founding build without production accounts, editor access, or billing. Security claims beyond the implemented public surface are not implied.