Vulnerability Disclosure Policy

Furcata values the work of security researchers and welcomes reports of potential vulnerabilities in our Services. This policy explains how to report a vulnerability and what you can expect from us.

1. Scope

This policy applies to vulnerabilities in systems and services that Furcata operates and controls, including our website, applications, and public APIs.

This policy does not apply to third-party services, to social engineering or physical attacks, or to vulnerabilities in systems we do not control. If you believe a third-party service is affected, report it to that provider.

2. How to Report

Send your report to security@furcata.com. Please include:

  1. A clear description of the vulnerability and its potential impact.
  2. The steps needed to reproduce it, including any proof-of-concept.
  3. The affected URL, endpoint, or component.
  4. Your contact details so we can follow up.

Please encrypt sensitive details where possible and avoid including personal data of others in your report.

3. Our Commitments

  1. We will acknowledge your report within 3 business days.
  2. We will investigate and keep you informed of our progress.
  3. We will not pursue legal action against researchers who follow this policy in good faith.
  4. We will credit you for a valid report if you wish, once the issue is resolved.

4. Your Commitments

When researching, you must:

  1. Act only in good faith and avoid privacy violations, data destruction, and disruption to our Services or to others.
  2. Access only the minimum data necessary to demonstrate the vulnerability, and do not exfiltrate, retain, or share data that is not yours.
  3. Give us reasonable time to fix the issue before disclosing it publicly.
  4. Not use social engineering, denial-of-service testing, or attacks against our customers or their contacts.

5. Out of Scope

  1. Reports generated solely by automated scanners without a demonstrated impact.
  2. Missing security headers or best-practice recommendations without an exploitable issue.
  3. Vulnerabilities requiring physical access to a device or a compromised end-user device.

6. Related Policies

7. Contact

Security reports: security@furcata.com. General support: support@furcata.com.