Security Bug Fix Policy(SLO)
Last updated: (July 29, 2026)
Open Source Consulting Inc. ("OSCI") makes it a priority to ensure that customers' systems cannot be compromised by exploiting vulnerabilities in OSCI products.
1. Scope
The following describes how and when we resolve security bugs in our products. It does not describe the complete disclosure or advisory process that we follow.
2. Security Bug Fix Service Level Objectives (SLO)
OSCI sets service level objectives for fixing security vulnerabilities based on the security severity level and the affected product. We have defined the following timeframes for fixing security issues in our products:
For purposes of this Policy:
'Cloud Product' means any OSCI product that OSCI makes available as a cloud-hosted application on the Atlassian Marketplace (i.e., operated by OSCI rather than installed by the customer). A current list of Cloud Products is available on OSCI's Atlassian Marketplace vendor page https://marketplace.atlassian.com/vendors/1213576/osci-open-source-consulting .
'Self-Managed Product' means any OSCI product distributed for installation and operation by the customer on customer-controlled infrastructure (e.g., Atlassian Data Center apps). A current list of Self-Managed Products is available on OSCI's Atlassian Marketplace vendor page https://marketplace.atlassian.com/vendors/1213576/osci-open-source-consulting .
'Previous Version' means, with respect to a given product, the immediately preceding Long-Term Support release.
Accelerated Resolution Timeframes
These timeframes apply to all Cloud Products of OSCI:
Critical severity bugs targeted to be fixed in product within 10 days of being verified
High severity bugs targeted to be fixed in product within 4 weeks of being verified
Medium severity bugs targeted to be fixed in product within 12 weeks of being verified
Low severity bugs targeted to be fixed in product within 25 weeks of being verified
Extended Resolution Timeframes
These timeframes apply to all self-managed products of OSCI:
Critical, High, and Medium severity bugs targeted to be fixed in product within 12 weeks of being verified
Low severity bugs targeted to be fixed in product within 25 weeks of being verified
3. Critical Vulnerabilities
When a Critical security vulnerability is discovered by OSCI or reported by a third party, OSCI will use commercially reasonable efforts to:
Issue a new, fixed release for the current version of the affected product as soon as possible.
Issue a new maintenance release for a previous version.
It is important to stay on the latest bug fix release for the version of the product you are using (this is best practice).
The critical vulnerabilities resolution process does not apply to our Cloud products as these services are always fixed by OSCI without any additional action from customers.
4. Non-Critical Vulnerabilities
When a security issue of a High, Medium or Low severity is discovered, OSCI will aim to release a fix within the service level objectives listed at the beginning of this document. The fix may also be backported to Long Term Support releases, if feasible (as determined by OSCI in its reasonable business judgment).
You should upgrade your installations when a bug fix release becomes available to ensure that the latest security fixes have been applied.
5. Customer Notification Process
When a security vulnerability is confirmed and a fix is being prepared or released, OSCI will notify affected customers through one or more of the following channels:
Email notification to the technical contact registered in the Atlassian Marketplace
In-product notification or release notes published at: Release Note List
Security advisory posted on the OSCI website or documentation portal
Notifications for Critical and High severity vulnerabilities will be sent as soon as a fix is available or, where disclosure is delayed for remediation purposes, within the SLO timeframe defined in Section 2.
For Medium and Low severity vulnerabilities, notifications will be included in regular release notes and changelogs.
6. Vulnerability Reporting
If you discover a security vulnerability in any OSCI product, please report it responsibly by contacting our security team at:
Email: atlassian_apps@osci.kr
7. SLO Disclaimer
THE SLO TIMEFRAMES DEFINED IN THIS DOCUMENT ARE OBJECTIVES, NOT GUARANTEES. OSCI WILL USE COMMERCIALLY REASONABLE EFFORTS TO MEET THESE OBJECTIVES, BUT SHALL NOT BE HELD LEGALLY LIABLE FOR FAILURE TO MEET ANY SLO TIMEFRAME. THESE SLO DO NOT CONSTITUTE A WARRANTY OF ANY KIND.
In no event shall OSCI be liable for any indirect, consequential, exemplary, incidental, special, or punitive damages arising from a security vulnerability, including but not limited to loss of data, loss of revenue, or loss of business, even if OSCI has been advised of the possibility of such damages.
Notwithstanding the foregoing, nothing in this Section 7 shall be construed to exclude or limit OSCI's liability for any damage arising from OSCI's willful misconduct or gross negligence.
8. Policy Changes and Retroactive Application
OSCI reserves the right to update or modify this Security Bug Fix Policy at any time. Changes to this policy will be published on our website and documentation portal.
Scenario | Applicable SLO Version |
Vulnerabilities reported before policy update | SLO in effect at time of initial report |
Vulnerabilities reported after policy update | Updated SLO applies |
We will continuously evaluate our policies based on customer feedback and will provide any updates or changes on our documentation page.
9. Other Information
Severity level of vulnerabilities is calculated based on Severity Levels for Security Issues, available at SLA.
10. Contact Us
For security-related inquiries or to report a vulnerability:
Email: atlassian_apps@osci.kr
Website: https://global.osci.kr/
Support Portal: https://cloud-osci.atlassian.net/servicedesk/customer/portals
Address: 32, Teheran-ro 83-gil, Gangnam-gu - 06167, Seoul, Korea (South)