Security at Opami

Version 2026-09-26

Reporting a vulnerability

Write to security@opami.ai. Tell us what you found, how to reproduce it, and what an attacker could do with it. Plain email is enough; we do not require encryption.

What you can expect

We will reply to you by email and tell you when it is fixed. If you want, we credit you by name.

Safe harbour

We will not pursue legal action, civil or criminal, against a researcher who reports a vulnerability to us in good faith. This applies on four conditions:

This protection does not extend to anyone acting in bad faith.

In scope and out of scope

No bug bounty

We do not pay for reports today. We say so plainly so that nobody spends a weekend expecting a reward.

If we have an incident

We investigate as soon as we learn of it, contain the problem first, and tell the people affected. Where the law requires it, we notify the Portuguese supervisory authority (CNPD) within 72 hours of becoming aware, and the users affected without undue delay when the risk to them is high. We publish what happened once it is contained. The privacy notice covers how we handle personal data.

Contact

security@opami.ai for security, privacy@opami.ai for data-protection requests, hello@opami.ai for everything else. Controller: Precious Episode LDA, VAT number PT514701617, Portugal.

In case of discrepancy between translations, the English version prevails.