Security & Responsible Disclosure
Last updated: July 19, 2026
Cyber Eclipse, the operator of the OpsGate service, welcomes reports of security vulnerabilities from the research community. This policy explains how to report a vulnerability responsibly and what you can expect from us in return.
1. Reporting a vulnerability
If you believe you have discovered a security vulnerability in OpsGate, please report it privately to security@opsgate.ca. Please do not disclose the issue publicly until we have had a reasonable opportunity to investigate and remediate it.
2. Information to include
- a clear description of the issue and its potential impact;
- steps to reproduce, including any proof of concept;
- the affected component (web console, API, or WordPress plugin), and version if known;
- a means for us to contact you for follow-up.
3. Our commitment
- We acknowledge good-faith reports promptly, normally within five business days.
- We investigate every credible report and keep you informed of our progress.
- We will not pursue legal action against researchers who act in good faith, comply with this policy, and avoid privacy violations, service disruption, and data destruction.
4. Scope and guidelines
In the course of your research, please:
- test only against your own account and your own connected sites;
- never access, modify, or delete data belonging to other users;
- avoid automated testing that degrades or disrupts the Service for others;
- refrain from social engineering, physical attacks, and denial-of-service techniques.
5. Confidentiality incidents
We maintain a register of confidentiality incidents. Where an incident presents a risk of serious injury, we take reasonable measures to reduce the risk and notify affected individuals and the Commission d'accès à l'information du Québec as required by law. Further detail is set out in our Privacy Policy.
Security contact: security@opsgate.ca