Back to MoryaOS
Security reporting
Responsible Disclosure
If you believe you have found a security issue, help us validate it without accessing other people's data or disrupting festival operations.
Last updated: 2026-08-26
Please do
Send reports to security@moryaos.com with:
- the affected URL, route, or feature
- a short impact statement
- safe reproduction steps or a minimal proof
- the account role or test context used, without credentials
Please do not
To protect devotees, operators, and festival services, do not:
- access, copy, alter, or disclose another person's data
- test against payment, provider, production, or emergency systems
- send passwords, OTPs, session tokens, private keys, or raw personal data
- perform denial-of-service, spam, social-engineering, or destructive tests
What happens next
MoryaOS will review a report when it contains enough information to identify and reproduce the concern. Do not assume a report is accepted, fixed, or eligible for recognition until the platform team confirms that directly.
Need help with this policy?
Contact MoryaOS at admin@moryaos.com. Never include a password, OTP, recovery code, or access token.
