# Question About OOS Closure for Elasticsearch Deployment on es.io

**URL:** <https://discuss.elastic.co/t/question-about-oos-closure-for-elasticsearch-deployment-on-es-io/385303>\
**Category:** Elastic Security\
**Created:** [March 2, 2026, 2:59pm UTC](https://discuss.elastic.co/t/question-about-oos-closure-for-elasticsearch-deployment-on-es-io/385303 "2026-03-02T14:59:51Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Attacker\_Tester](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/attacker_tester/32/140410_2.png) [@Attacker\_Tester](https://discuss.elastic.co/u/Attacker_Tester)\
**Post date:** [March 2, 2026, 2:59pm UTC](https://discuss.elastic.co/t/question-about-oos-closure-for-elasticsearch-deployment-on-es-io/385303/1 "2026-03-02T14:59:51Z")

</div>

I noticed that my report regarding a potential DoS bug in the instant Elasticsearch deployment on **[es.io](http://es.io)** was marked as out-of-scope (OOS). Could you please clarify why this deployment/domain is considered OOS? I want to make sure I fully understand the scope for future reports.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 2, 2026, 3:16pm UTC](https://discuss.elastic.co/t/question-about-oos-closure-for-elasticsearch-deployment-on-es-io/385303/2 "2026-03-02T15:16:06Z")

</div>

Hi @Attacker_Tester

Welcome to the community.

All questions / answers about security should be routed to

[security@elastic.co](mailto:security@elastic.co)

> **[Product Security at Elastic](https://www.elastic.co/product-security)**
>
> Safeguarding our customers and community is our top priority; they are at the heart of everything we do. We deeply value our partnership with the security community, and share the goal of keeping our ...
