Security & vulnerability disclosure

We take the security of Office EU and our users seriously. If you believe you have found a security vulnerability, we encourage you to report it to us in a responsible way.

How to report

For sensitive reports you may encrypt your message using our PGP public key.

What to expect

We will acknowledge your report as soon as possible and work with you to understand and address the issue. We follow a coordinated vulnerability disclosure process: we will not take legal action against or ask for the arrest of researchers who report in good faith and in line with this policy.

Out of scope

Please do not perform testing that could harm our services or users (e.g. denial of service, social engineering, or physical attacks). Only access or test systems you are authorised to use or that are clearly intended for public testing.

← Back to Office EU