Security policy
Frameleaf Cloud welcomes reports from security researchers. This policy says what's in scope, how to reach us, how quickly we respond and how we protect you when you research in good faith.
Contact
Report vulnerabilities privately to [email protected]. Don't open a public issue or discuss the problem in public before it's fixed.
- Say what you found, how to reproduce it and the impact you expect.
- Include the affected host, the time (UTC) and any request ids from error responses.
- If you want to encrypt your report, ask for our current key in your first message.
Scope
In scope:
id.frameleaf.cloud(sign-in and the identity provider)api.frameleaf.cloud(the API self-hosted servers call)frameleaf.cloud(the account site;account.frameleaf.cloudonly redirects there)ml.eu.frameleaf.cloudandml.na.frameleaf.cloud(cloud processing)- the Frameleaf Cloud relays (
*.relays.frameleaf.cloud) and theframeleaf.netname servers status.frameleaf.cloud(the status page)
Out of scope:
- the self-hosted Frameleaf server, which has its own policy in its open-source repository
- the marketing site (
frameleaf.app) and the help centre (help.frameleaf.app), which aren't part of Frameleaf Cloud; you can still tell us about a problem with them at the address above - a server's own hostname under
frameleaf.net, or a custom hostname, beyond the relay itself: those belong to their owners - denial of service, load or volume testing, and spam
- social engineering, phishing and physical attacks against Frameleaf staff, customers or providers
- reports from automated scanners without a demonstrated impact, missing headers without an exploit, and self-XSS
- third-party services we use (payment, email and hosting providers): report those to the provider
Rules for research
- Use only accounts and servers you own or have written permission to test.
- Don't access, change or keep data that isn't yours. If you reach someone else's data, stop, don't copy it and tell us straight away.
- Don't degrade the service for others: no denial of service, no brute forcing beyond what proves the issue, and respect rate limits.
- Give us a reasonable time to fix before you disclose: 90 days from your report, or sooner by agreement once the fix ships.
Safe harbour
If you research and report in good faith and follow the rules above, we consider your research authorized. We won't pursue or support legal action against you for it, including under anti-hacking laws or our terms of service, and we'll say so publicly if a third party does. If you're unsure whether something is allowed, ask us first.
Response times
| Step | Target |
|---|---|
| Acknowledge your report | 3 business days |
| Triage and a first assessment with a severity | 7 days |
| Fix a critical issue | 7 days |
| Fix a high issue | 30 days |
| Fix a medium or low issue | 90 days |
We keep you updated until the fix ships, credit you in the release notes if you want, and tell you before we publish anything about the issue. There's no paid bounty programme at the moment.
Personal data
Incidents that involve personal data follow our 72-hour breach process: we assess, contain and, where the law requires, notify the supervisory authority within 72 hours and tell the people affected.