Onapsis Vulnerability Disclosure
Onapsis publishes two distinct, separate disclosure documents. The inbound policy — "Security Vulnerability Reporting Guidelines" — governs reports about Onapsis's own products and web properties. The outbound policy — the Onapsis Research Labs "Disclosure Policy" — governs how Onapsis reports vulnerabilities it finds in third-party vendor software (SAP, Oracle) and when it publishes an advisory. Both are public and were fetched at HTTP 200. The automated probe recorded neither because Onapsis serves no /.well-known/security.txt (404) and hosts its inbound policy at a non-standard path; this is the searched, human-verified fill.
Onapsis publishes a vulnerability disclosure policy for reporting security issues. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.
Disclosure Policy
Security Contact
Source
Vulnerability Disclosure
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.