Skip to main content
OpenIRB

Responsible Disclosure

Report a vulnerability

We welcome good-faith security research and will work with you to verify and remediate issues.

Scope

This policy covers the OpenIRB website and its contact endpoint. Please do not access, modify, or exfiltrate data that is not your own, and do not run denial-of-service tests.

How to report

Send a detailed report — affected URL, steps to reproduce, and impact — through the contact form selecting “Other,” or to the security contact published at launch. Do not include exploit payloads against third parties or any sensitive personal data.

Our commitment

We will acknowledge valid reports, keep you updated on remediation, and credit researchers who follow this policy and act in good faith.

Last reviewed 2026-06-14. This is informational, not legal advice.