Skip to main content

Vulnerability Disclosure

If you believe you found a vulnerability in OASIS, contact Usatii Media with enough detail to reproduce it. We will acknowledge the report, validate impact, and coordinate remediation and disclosure in good faith.

Reviewed September 15, 2026

Control details

Include

  • The affected URL or component, steps to reproduce, observed impact, relevant timestamps, and a safe proof of concept.
  • Do not include unrelated personal data or customer content.

Good-faith research

  • Avoid privacy violations, service disruption, social engineering, physical testing, denial of service, automated high-volume scanning, and access or changes beyond the minimum needed to demonstrate impact.

Protect data

  • Stop testing and report immediately if you encounter credentials, personal data, confidential records, or another customer’s content.
  • Do not download, retain, or share that data.

Our response

  • We aim to acknowledge credible reports, maintain a channel during validation, prioritize based on demonstrated risk, and coordinate public disclosure when appropriate.

Scope

  • The OASIS application and public properties operated by Usatii Media are in scope.
  • Third-party networks, customer systems, and services not operated by Usatii Media are out of scope.

Important: This disclosure process does not offer a bug bounty or authorize violations of law, contracts, privacy, or service availability.