Responsible Disclosure
Report a vulnerability
We welcome good-faith security research and will work with you to verify and remediate issues.
Scope
This policy covers the OpenIRB website and its contact endpoint. Please do not access, modify, or exfiltrate data that is not your own, and do not run denial-of-service tests.
How to report
Send a detailed report — affected URL, steps to reproduce, and impact — through the contact form selecting “Other,” or to the security contact published at launch. Do not include exploit payloads against third parties or any sensitive personal data.
Our commitment
We will acknowledge valid reports, keep you updated on remediation, and credit researchers who follow this policy and act in good faith.
Last reviewed 2026-06-14. This is informational, not legal advice.