ONLYOFFICE, the open-source office suite used by governments, universities, and enterprises for document collaboration, published a post on 15 July 2026 covering the ways its community contributes to the product. Its section on security research names us directly, thanking “isopach (is-)” for “submitting numerous reports via the platform.”
The surrounding context gives a sense of the volume the programme handles. ONLYOFFICE notes that “starting from the release of version 9.0, we have fixed more than 2,500 bugs and vulnerabilities across the online and desktop editors”, a figure it attributes to the combined work of community members, customers, partners, and researchers on its HackerOne programme.
Our submissions were made under the HackerOne handle is-, the account Isopach uses for bug bounty work.
Why this is a partial disclosure
We are able to confirm the credit and nothing beyond it. The individual reports remain governed by the disclosure terms of ONLYOFFICE’s HackerOne programme, which means the vulnerability classes, affected components, severities, and technical detail stay private unless and until the vendor elects to disclose them. That is the correct outcome and we are not seeking to shortcut it. A vendor that has fixed an issue quietly for a large installed base of self-hosted deployments has a legitimate interest in controlling when the details become searchable, because self-hosted users patch on their own schedule and a public writeup arrives for defenders and attackers at the same moment.
What we can say is the shape of the engagement. Working a mature programme like this one is a different discipline from one-off vulnerability research. Reports have to be reproducible against a specific build, scoped to what the vendor actually ships rather than to a misconfigured test instance, and written so that a triage engineer who has never seen your setup can confirm the finding without a back-and-forth. Sustained credit from a vendor is, in our experience, a better signal of that discipline than any single high-severity finding.
Why we do this
Isopach has run open-source and product security research under its own name since 2017, and the work predates and feeds the consulting practice rather than sitting beside it as marketing. Bug bounty programmes are where you encounter modern codebases under real maintenance, with maintainers who push back on weak findings and triage teams who will tell you plainly when a report is not worth their time. That feedback loop is difficult to reproduce internally, and it is the reason our client assessments are grounded in defects that vendors have actually accepted and fixed rather than in scanner output.
The ONLYOFFICE post is 16 ways to contribute to ONLYOFFICE, published 15 July 2026. The programme itself is invitation-only rather than open to public submissions, and Isopach takes part as one of its invited researchers.