Security / Responsible disclosure

Report security concerns without creating new risk

Omnimesh welcomes good-faith reports about suspected vulnerabilities affecting public services for which OMNIMESH LTD is responsible.

The Omnimesh transport system is development-stage and is not offered as a public testing target. Do not test non-public systems, repositories, people or infrastructure without explicit written authorisation.

Scope

Public Omnimesh web properties only

Where a service is operated by a third party, report vulnerabilities in that provider's platform to the provider unless the issue arises from an Omnimesh configuration or implementation.

In scope

  • omnimesh.co.uk and its public first-party pages.
  • Public contact endpoints or assets explicitly identified as operated by OMNIMESH LTD.
  • Security misconfiguration or data exposure demonstrably caused by Omnimesh.

Out of scope

  • Denial-of-service, destructive, persistence or availability testing.
  • Social engineering, phishing, physical access or attacks on team members.
  • Accessing, modifying, retaining or sharing another person's data.
  • Third-party platform vulnerabilities unrelated to Omnimesh configuration.
  • Non-public product code, systems or infrastructure without written authorisation.

Initial report

Send the minimum needed to establish relevance

Email support@omnimesh.co.uk with the subject line [Security] Vulnerability disclosure.

Include the affected public URL or service, a concise description, the date observed and a safe summary of impact. Do not include credentials, personal data, classified information, operational details, weaponised exploit code or extensive logs in the first message.

Omnimesh will establish an appropriate channel before requesting sensitive technical detail. No fixed acknowledgement or remediation service level is currently published; reports will be prioritised according to credible impact and available evidence.

Researcher expectations

Keep testing proportionate and reversible

Good-faith research should minimise harm, stop when sensitive data or material service impact becomes possible, and give Omnimesh a reasonable opportunity to investigate before public disclosure.

  1. 01

    Use the least intrusive method capable of confirming the issue.

  2. 02

    Stop immediately if testing could affect availability, confidentiality, integrity or another person.

  3. 03

    Do not exploit beyond the minimum evidence needed to demonstrate the concern.

  4. 04

    Do not publish details while remediation or safe coordination is actively under discussion.