Report vulnerabilities to security@outemit.dev. Do not file public GitHub issues with exploit details. There is no published bug bounty.
This SLA is an operational target for the mailbox we publish. It is not a contractual commitment and does not imply that the mailbox is staffed 24/7.
Report phishing, spam, or account abuse to the same address with subject line Abuse:. Include URLs, timestamps, and tenant IDs when you have them. Do not attach payloads that contain secrets.
We have not completed an independent penetration test. Do not treat this page as a compliance claim (SOC 2, GDPR adequacy, or similar).