Responsible Disclosure Policy
Last updated: August 2, 2026
Security research makes everyone safer. If you believe you have found a vulnerability in one of our systems, we want to hear from you — and we commit to working with you transparently and quickly.
Report vulnerabilities to our security team, encrypted if possible:
1. How to Report
Email [email protected] with a description of the issue, the affected URL or component, steps to reproduce, and any proof-of-concept. Please encrypt sensitive reports with our PGP key. Do not open a public issue or disclose the finding before we have addressed it.
2. Our Commitments
We acknowledge reports within 2 business days, provide a status update at least every 7 days, and target remediation within 7 days for critical issues, 30 days for high severity, and 90 days for medium and low severity. We will credit you in our acknowledgments if you wish.
3. Safe Harbor
We will not initiate legal action against researchers who act in good faith: make every effort to avoid privacy violations and service disruption, do not access or exfiltrate data beyond what is necessary to demonstrate the issue, and give us reasonable time to remediate before any public disclosure.
4. Scope
In scope: brainfortsecurity.com and its subdomains. Out of scope: denial-of-service testing, social engineering, physical attacks, spam, and vulnerabilities in third-party services we use (report those to the respective vendor).