Onapsis Vulnerability Disclosure
Onapsis publishes two distinct, separate disclosure documents. The inbound policy — "Security Vulnerability Reporting Guidelines" — governs reports about Onapsis's own products and web properties. The outbound policy — the Onapsis Research Labs "Disclosure Policy" — governs how Onapsis reports vulnerabilities it finds in third-party vendor software (SAP, Oracle) and when it publishes an advisory. Both are public and were fetched at HTTP 200. The automated probe recorded neither because Onapsis serves no /.well-known/security.txt (404) and hosts its inbound policy at a non-standard path; this is the searched, human-verified fill.
Onapsis publishes a vulnerability disclosure policy for reporting security issues. A machine-readable /.well-known/security.txt is served. A dedicated security contact is published.