Security at Opus Options Trading

Reporting a vulnerability

If you've found a security issue, please email security@opusoptionstrading.com. Include a short description, a reproduction (steps, payload, or a video), and the impact you believe it has. One report per email please.

What we promise

  • An acknowledgement within 72 hours of receipt.
  • A status update within 7 days with our triage decision (in-scope / out-of-scope / duplicate), severity, and target fix date.
  • Credit on the hall-of-fame page after the fix ships, with your name + handle (or anonymous, your choice).
  • No legal action against good-faith researchers who follow this policy — we won't sue, won't involve law enforcement, won't terminate your account.

What we ask

  • Test against your own account only — don't access, modify, or download other users' data.
  • No automated scanners that generate sustained load against production. Brief manual probing is fine; running Burp / ZAP for hours is not.
  • Don't publicly disclose the issue until we've shipped a fix or 90 days have passed (whichever is sooner). If we're not moving fast enough, tell us — we'd rather hear that than read about it on Twitter first.
  • Stop and email us immediately if you find data belonging to other users. Don't keep copies.

In scope

  • The web app and API at opusoptionstrading.ai + subdomains
  • Authentication, session, and account-recovery flows
  • Cross-tenant data access (IDOR), privilege escalation
  • Injection (SQL, NoSQL, command, template), SSRF, XXE
  • Cross-site scripting (stored, reflected, DOM-based)
  • CSRF on state-changing endpoints
  • Insecure direct object references in API routes
  • Sensitive data exposure (logs, error messages, repo leaks)
  • Business-logic flaws that move money or modify positions
  • Cryptographic weaknesses (weak signing, predictable tokens)

Out of scope

These are typically reported but we won't reward / triage them unless they chain into something exploitable:

  • Missing security headers on static-asset paths (icons, fonts, images)
  • Rate-limit bypasses that don't lead to data access or meaningful cost — we acknowledge them, we don't reward.
  • Self-XSS, clickjacking on pages without sensitive actions, UI redress without impact
  • Reports based solely on automated-scanner output (Nessus, Acunetix) without a working PoC
  • Issues in third-party services we don't operate (Stripe, Polygon, Resend) — report those to the upstream
  • Subdomain takeover claims on subdomains we don't actually own
  • Best-practice suggestions (e.g. "you should add SRI") that aren't tied to a specific exploitable case

Bounty / rewards

We don't have a paid bounty program yet. We acknowledge, triage, fix, and credit. When we set up a paid program, this page will be updated with the payout matrix and we'll back-pay credited researchers retroactively for the highest-severity issues.

This policy is published in good faith and will be updated as our security posture matures. Last updated 2026-05-11. Return to Opus Options Trading.