Security
Operon Systems LLC, doing business as Operon Group
Last updated: September 24, 2026
Report a website concern
If you believe you have found a security issue on this website, please contact Operon and mention “Website security” in your message. Include the affected page and a description that does not expose sensitive information.
Do not include passwords, access tokens, patient information, or other people’s records. Do not access, alter, or disclose data belonging to others or disrupt the website while documenting a concern.
Alternative reporting channel
If the form is unavailable or is the subject of your report, email jweber@theoperongroup.com with “Website security” in the subject. Include the affected URL, a minimal description, and safe reproduction steps. Redact personal information and secrets. If you encounter exposed information, stop accessing it and report what happened without downloading additional records.
Research boundaries
This page is not authorization for penetration testing, automated vulnerability scanning, social engineering, denial-of-service testing, credential attacks, or testing third-party systems. Obtain written authorization and scope before active security testing. Do not contact or impersonate customers or staff to demonstrate an issue. No bounty or other payment is promised.
Sharing project information
This public website does not provide a client login or file-upload service. Ordinary email and the public form are not approved channels for regulated records, credentials, or sensitive project files. Before sharing confidential materials, agree with Operon on a transfer method and applicable confidentiality, access, and data-processing terms.
Controls and limitations
The contact handler validates required fields and message size, checks request origin, uses a spam-trap field, and uses bot verification and shared submission limits on the hosted site. If these checks are unavailable, form delivery stops and visitors can use the email address above. Browser security policies restrict framing and resource loading. Delivery credentials are used on the server. These controls reduce some risks; they do not guarantee protection against every attack or provider outage.
This statement is not a claim of SOC 2, ISO 27001, HIPAA, or other security certification or comprehensive compliance. Security incidents and any required notices must be handled under applicable law and relevant agreements. Privacy requests and security reports may be retained as needed to investigate and document their resolution.
Website information
Read the Privacy Policy for information about the website’s features and hosting, and the Professional Services Disclaimer for the role of human review in technology and AI-assisted work.