Security

Report a vulnerability.

Tell us what you found, where, and what you did to prove it. A person reads it, and that person answers.

01 / Scope

What to look at

Out of scope means we will not act on it, not that we mind you looking.

Targets in and out of scope for this policy
TargetStateWhy
forgecore.ai+In scopeThe public site
app.forgecore.ai+In scopeThe signed-in platform
Physical attacks on hardware×Out of scopeNothing is on a road yet
Social engineering×Out of scopeOf our staff or our vendors
Denial of service×Out of scopeLoad is not a finding
Scanner output, no impact shown×Out of scopeShow us the impact
The mesh radio and the pylonAsk firstWrite and we will arrange it

02 / Safe harbor

We will not come after you

Report a bug to us in good faith and we will not take legal action against you. We will not ask anyone else to either.

Good faith means three things. You did not access, change or destroy anyone else's data. You did not slow the service down for other people. You gave us a fair chance to fix it before you told anyone else.

03 / Promises

Five promises, all small enough to keep

First reply
Within three working days
Who reads it
A person. Two founders triage by hand
The fix
We tell you when it ships
Credit
Named here, if you want to be
Money
None, and we would rather say so

We are two founders with no one else on call. Each line above is one we can keep, not one that just sounds good.

04 / Contact

Where to send it

A machine can read our contact details at /.well-known/security.txt. A report about this site will be short. The site loads nothing from another host and runs one small script, written into the page itself, which reads your theme choice. Check that in your own network tab.

security@forgecore.aiThe control register