Diligence and security disclosure

01 · TECHNICAL DILIGENCE PROCESS

The next step, made concrete.

  1. Scope the decision — product evaluation, partner enablement, data handling or architecture.
  2. Confirm participants — sponsor, architect, SOC owner, legal/risk as required.
  3. Put appropriate controls in place — NDA and secure material exchange where needed.
  4. Review the deployment — trust boundaries, data flow, target classes, integrations, responsibilities.
  5. Walk one example path — from hostile activity to observation, Finding, supporting evidence and workflow, using currently available Access Finding family material.
  6. Record open conditions — deployment-specific limits, security actions, commercial next step.
Public diligence pack may includeUnder NDA may include
conceptual architecture · deployment patterns · responsibility model · current output paths · data-category overview · claim and limitation summary · a sanitized Finding/evidence exampledetailed architecture · deployment-specific conditions · sample evidence · failure modes · security controls · data-handling details · current operational status
02 · SECURITY DISCLOSURE

Report a security issue through the coordinated route.

Found a security issue? Do not send vulnerability details through the commercial contact route. Use OHIIHO’s coordinated security-disclosure route: security@ohiiho.com, documented at /security/ and /.well-known/security.txt.

The security route defines in-scope public systems and disclosure coordination. If you need an encrypted channel, say so in your first email and we will share instructions. Please act in good faith and give OHIIHO reasonable time to remediate before any public disclosure.