Legal
Security
Last updated September 17, 2026
Reporting a vulnerability
If you believe you have found a security vulnerability in openstudio.tech or in OpenStudio itself, email hello@openstudio.tech with the steps to reproduce it. We acknowledge within 2 business days and triage within 5. Please give us reasonable time to fix the issue before disclosing it publicly.
We do not run a bug bounty. We read every report, and we credit researchers who want credit.
Scope
In scope: openstudio.tech and the OpenStudio application, its APIs, and its CLI.
Out of scope: social engineering, physical attacks, and denial of service.
Good-faith research
We will not pursue action against security research conducted in good faith and within the scope above — research that avoids accessing or altering other people’s data, does not degrade the service, and reports what it finds rather than exploiting it.
Controls
Data is encrypted in transit (TLS 1.2 and above) and at rest (AES-256). Production access is role-based, least-privilege, and requires multi-factor authentication, with audit logs recording timestamp, actor, and action. Further detail, and the compliance documentation, is at trust.costa.app.
Machine-readable
This policy is also published at /.well-known/security.txt, per RFC 9116.