Report a security vulnerability.
Send the affected system, the steps to reproduce the issue, its impact, and whether you accessed any data. Follow the scope and safe-harbor terms below.
Write to info@forgecore.ai with "security" in the subject line. Plain text is fine. Ask for an encryption key if the report contains sensitive details.
| The thing | Where it stands | What that means |
|---|---|---|
| forgecore.ai, every page on it | In scope | Including the gate on the investor pages. Tell us if you get past it. |
| app.forgecore.ai, the portal and the console | In scope | Where customers and staff sign in. Test only with accounts and data you are authorized to use. |
| The software on a pylon | In scope | Ask us first. We will tell you which unit is a bench rig on private ground and which is on a public pole. |
| Our mail, our DNS, our cloud accounts | From outside | Report exposed access without entering accounts or systems you are not authorized to use. |
| Opening a box on a public road | Ask first | Coordinate with Forge Core first so the road owner can approve supervised access. |
| Systems belonging to the companies we use | Not ours | AWS and the rest run their own programs and their own rules. The sub-processor page lists who they are. |
| Denial of service, spam, or social engineering | Out of scope | Do not disrupt service, send bulk messages, or target staff through deception. |
If you follow this section, Forge Core won't take legal action against you for your research, and won't report you to anybody else for it.
SH-1
We will treat research that follows this section as authorized. We won't bring a claim against you under the Computer Fraud and Abuse Act or under section 502 of the California Penal Code, and we won't refer you to anyone else for it.
SH-2
We won't bring a claim under the Digital Millennium Copyright Act for work you did to find or prove a flaw in a system of ours.
SH-3
If a third party takes action against you for research that followed this section, we will say in writing, to them or to a court, that the work was authorized by us.
SH-4
This holds while you act in good faith. Stop at the first thing you find. Take no more data than proving the flaw needs, and tell us if you took any. Change nothing and delete nothing. Don't degrade the service for anybody else. Give us the time in section 3 before you publish.
SH-5
If you aren't sure whether something is in scope, ask. Asking never voids this section. Guessing might.
If this wording changes, the previous wording will remain available with the change date.
| Three working days | A reply from a person, naming who is handling it. Not a ticket number on its own. |
| Ten working days | Our judgement: whether we agree it is a flaw, how bad we think it is, and whether we are fixing it. |
| Ninety days | A fix, or a written reason why not and what we did instead. If we need longer we will tell you before the ninety days, not after. |
| The day we fix it | If it touched customer data it goes in the public log. You are named there if you want to be, and left out if you don't. |
| Never | No cash bounty is offered. With your consent, we can provide public credit after the issue is resolved. |
What is useful to send
Include the affected system, numbered steps, expected and actual results, impact, and any data accessed. A screenshot or short proof can help when it does not expose additional data.