Security policy

Frameleaf Cloud welcomes reports from security researchers. This policy says what's in scope, how to reach us, how quickly we respond and how we protect you when you research in good faith.

Contact

Report vulnerabilities privately to [email protected]. Don't open a public issue or discuss the problem in public before it's fixed.

Scope

In scope:

Out of scope:

Rules for research

Safe harbour

If you research and report in good faith and follow the rules above, we consider your research authorized. We won't pursue or support legal action against you for it, including under anti-hacking laws or our terms of service, and we'll say so publicly if a third party does. If you're unsure whether something is allowed, ask us first.

Response times

StepTarget
Acknowledge your report3 business days
Triage and a first assessment with a severity7 days
Fix a critical issue7 days
Fix a high issue30 days
Fix a medium or low issue90 days

We keep you updated until the fix ships, credit you in the release notes if you want, and tell you before we publish anything about the issue. There's no paid bounty programme at the moment.

Personal data

Incidents that involve personal data follow our 72-hour breach process: we assess, contain and, where the law requires, notify the supervisory authority within 72 hours and tell the people affected.