Security and responsible disclosure
Security Policy
This policy explains the core rules for Ordiva service security and good-faith security reporting.
Effective date: June 18, 2026
1. Security approach
Ordiva aims to protect platform security through authentication, role-based authorization, tenant isolation, secure environment variables, rate limiting, logging, error monitoring, and regular maintenance.
2. Responsible disclosure scope
Unauthorized access, data leakage, authentication bypass, tenant isolation issues, sensitive information exposure, or exploitable security vulnerabilities are within good-faith reporting scope.
3. Reporting rules
- Do not access, modify, download, or delete real user or customer data.
- Do not perform social engineering, phishing, spam, DDoS, physical attacks, or tests that harm third-party services.
- Allow Ordiva a reasonable review and remediation period before public disclosure.
- Include impact, reproduction steps, screenshots or safe evidence, and contact details in the report.
4. Security contact
Security reports may be sent to help@ordivaapp.com with the subject “security disclosure”. This page will be updated when a separate security address is created.
5. Bounty and safe harbor
Ordiva does not commit to a bug bounty program unless separately announced. The goal is to work constructively with reporters who perform good-faith, limited, non-harmful research; unlawful, harmful, or data-breaching conduct is outside this scope.