Disclosure

Scope, safe harbor, and response

Report a security vulnerability.

Send the affected system, the steps to reproduce the issue, its impact, and whether you accessed any data. Follow the scope and safe-harbor terms below.

Write to info@forgecore.ai with "security" in the subject line. Plain text is fine. Ask for an encryption key if the report contains sensitive details.

1  /  What is in scope

A glyph and a word, so nothing here depends on you seeing a color

The thingWhere it standsWhat that means
forgecore.ai, every page on itIn scopeIncluding the gate on the investor pages. Tell us if you get past it.
app.forgecore.ai, the portal and the consoleIn scopeWhere customers and staff sign in. Test only with accounts and data you are authorized to use.
The software on a pylonIn scopeAsk us first. We will tell you which unit is a bench rig on private ground and which is on a public pole.
Our mail, our DNS, our cloud accountsFrom outsideReport exposed access without entering accounts or systems you are not authorized to use.
Opening a box on a public roadAsk firstCoordinate with Forge Core first so the road owner can approve supervised access.
Systems belonging to the companies we useNot oursAWS and the rest run their own programs and their own rules. The sub-processor page lists who they are.
Denial of service, spam, or social engineeringOut of scopeDo not disrupt service, send bulk messages, or target staff through deception.

2  /  Safe harbor

An undertaking. Fixed wording, numbered so it can be cited.

If you follow this section, Forge Core won't take legal action against you for your research, and won't report you to anybody else for it.

SH-1

We will treat research that follows this section as authorized. We won't bring a claim against you under the Computer Fraud and Abuse Act or under section 502 of the California Penal Code, and we won't refer you to anyone else for it.

SH-2

We won't bring a claim under the Digital Millennium Copyright Act for work you did to find or prove a flaw in a system of ours.

SH-3

If a third party takes action against you for research that followed this section, we will say in writing, to them or to a court, that the work was authorized by us.

SH-4

This holds while you act in good faith. Stop at the first thing you find. Take no more data than proving the flaw needs, and tell us if you took any. Change nothing and delete nothing. Don't degrade the service for anybody else. Give us the time in section 3 before you publish.

SH-5

If you aren't sure whether something is in scope, ask. Asking never voids this section. Guessing might.

If this wording changes, the previous wording will remain available with the change date.

3  /  What we promise back

The clock starts when your mail arrives, not when we get to it

Three working daysA reply from a person, naming who is handling it. Not a ticket number on its own.
Ten working daysOur judgement: whether we agree it is a flaw, how bad we think it is, and whether we are fixing it.
Ninety daysA fix, or a written reason why not and what we did instead. If we need longer we will tell you before the ninety days, not after.
The day we fix itIf it touched customer data it goes in the public log. You are named there if you want to be, and left out if you don't.
NeverNo cash bounty is offered. With your consent, we can provide public credit after the issue is resolved.

What is useful to send

Include the affected system, numbered steps, expected and actual results, impact, and any data accessed. A screenshot or short proof can help when it does not expose additional data.

Write to usHow it is built, in full