Skip to content
Launching Oct 10 — OpenPush is free forever to 1M MAU per app, every feature included. Get early access →
ProductJourneysLive ActivitiesPricingCompareDocsChangelogMigrate from OneSignalSign in
openpush.ai · Legal

Vulnerability disclosure.

If you find something, we want to hear about it, and we will not come after you for telling us. Here is exactly what that means.

In force since 5 August 2026 · Last updated 5 August 2026 · Operated by SuperTuned Inc

In force now. This page is operative from the date above, because it covers something happening today rather than something that starts at launch. We will not change it retroactively: if it is amended, the date above changes and the previous version stays available on request from legal@openpush.ai.

How to report

Email security@openpush.ai. Include what you found, the steps to reproduce it, what an attacker could do with it, and how you would like to be credited. If you would rather stay anonymous, say so and we will respect it.

The same address is published at /.well-known/security.txt.

What we commit to

  • Acknowledgement within 2 business days. A human reply, not an autoresponder.
  • An assessment within 10 business days — whether we agree it is a vulnerability, how severe we think it is, and roughly when we expect to fix it.
  • Updates until it is closed, and a note when the fix ships.
  • Credit if you want it. We will name you when we write the fix up, unless you ask us not to.
  • No legal threats for good-faith research. See safe harbour below.

Safe harbour

If you follow this policy in good faith, we will not initiate or support legal action against you for your research, and we will not report you to law enforcement. If a third party brings action against you for activity that complied with this policy, we will make it known that your research was authorised.

Acting in good faith means all of the following:

  • You test only against accounts and data that are yours. If you need a second account to demonstrate something, create one — do not use a stranger's.
  • You stop as soon as you have confirmed a vulnerability. Proving access is enough; you do not need to enumerate a database to make the point.
  • You do not access, modify, exfiltrate, or retain anyone else's data. If you come across someone else's data by accident, stop and tell us.
  • You do not degrade the service — no denial of service, no load testing, no spam or social engineering of our staff, our users, or our vendors.
  • You give us a reasonable window to fix it before publishing. Our default ask is 90 days, and we are happy to agree something shorter for a low-severity issue or longer for one that is genuinely hard to fix. We will not use the window to stall you.

In scope

openpush.ai, app.openpush.ai, our API, and the published client SDK. Anything that lets someone reach another tenant's data, send on another tenant's behalf, escalate privileges, or bypass authentication is exactly what we most want to hear about.

Out of scope

Reports that are really scanner output with no demonstrated impact; missing headers or cookie flags with no exploit path; issues that require a rooted or physically compromised device; social engineering; and denial of service. Vulnerabilities in Apple's APNs or Google's FCM belong to Apple and Google — report those to them, though we would like to know if it affects our users.

What we do not offer

There is no paid bug bounty. We are a small team and we would rather be honest about that than advertise a reward programme we cannot run properly. What you get is a fast, human response, credit, and a fix. If that changes, this page changes first.

The wider picture of what is and is not in place is on the security page.

Who operates this service

SuperTuned Inc
1 Sansome Street, San Francisco, CA 94104, USA

Privacy: privacy@openpush.ai · Legal: legal@openpush.ai · Security: security@openpush.ai