DISCLOSURE GUIDELINES

DISCLOSURE GUIDELINES

Disclosure Policy

Disclosure Policy

Disclosure Policy

Responsible Disclosure Policy

Otonomii is committed to the security of our platform and the data entrusted to us. We welcome responsible disclosure of security vulnerabilities from the research community. This policy outlines the scope, expectations and protections for security researchers who identify and report vulnerabilities in good faith.

COVERED VULNERABILITIES

COVERED VULNERABILITIES

COVERED VULNERABILITIES

Remote code execution

Remote code execution

SQL injection

Authentication bypass

Authentication bypass

Privilege escalation

Model prompt injection

Model prompt injection

Server side request forgery

SQL injection

Privilege escalation

Server-side request forgery

EXCLUDED ITEMS

SUBMISSION REQUIREMENTS

Denial of service (DoS/DDoS) attacks

Detailed description of the vulnerability

Social engineering or phishing

Steps to reproduce the issue

Physical security issues

Proof of concept (code, screenshots or logs)

Third-party service vulnerabilities

Affected endpoint, service or component

Issues requiring physical device access

Estimated severity and potential impact

Automated scan output without proof of concept

Your contact information for follow-up

Vulnerabilities in out of scope assets

Denial of service (DoS/DDoS) attacks

Detailed description of the vulnerability

Social engineering or phishing

Steps to reproduce the issue

Physical security issues

Proof of concept (code, screenshots or logs)

Third-party service vulnerabilities

Affected endpoint, service or component

Issues requiring physical device access

Estimated severity and potential impact

Automated scan output without proof of concept

Your contact information for follow-up

Vulnerabilities in out of scope assets

Denial of service (DoS/DDoS) attacks

Detailed description of the vulnerability

Social engineering or phishing

Steps to reproduce the issue

Physical security issues

Proof of concept (code, screenshots or logs)

Third-party service vulnerabilities

Affected endpoint, service or component

Issues requiring physical device access

Estimated severity and potential impact

Automated scan output without proof of concept

Your contact information for follow-up

Vulnerabilities in out of scope assets

SCOPE

SCOPE

COVERED VULNERABILITIES

This policy covers all Otonomii owned web applications, APIs, infrastructure and AI model endpoints accessible at otonomii.com and related subdomains. Only vulnerabilities discovered through non-destructive testing methods are eligible.

This policy covers all Otonomii owned web applications, APIs, infrastructure and AI model endpoints accessible at otonomii.com and related subdomains. Only vulnerabilities discovered through non-destructive testing methods are eligible.

Autonomous Intelligence For The Next Era of Finance
Logo

2026 © Otonomii LTD. All rights reserved.

TOP

Autonomous Intelligence For The Next Era of Finance
Logo

2026 © Otonomii LTD. All rights reserved.

TOP