Security

Our vulnerability disclosure policy for formudex.io and anything else Formudex operates.

Report a vulnerability

Email security@formudex.io. Contact details are also available in /.well-known/security.txt.

A useful report includes:

  • The affected host, URL or service.
  • The issue and its impact.
  • Reproduction steps and relevant request or response details.
  • What you did and did not do while testing.
  • Your preferred credit, if any.

Please write in English. To send sensitive details encrypted, ask in your first message, without those details, and we will arrange a way to do so.

What is covered

In scope: formudex.io, its subdomains and any publicly reachable service operated by Formudex. Today that is a static site hosted on GitHub Pages, with email on Google Workspace. There are no accounts, forms or Formudex-run servers.

Out of scope:

  • Volumetric denial-of-service, load testing and anything that degrades service for other people.
  • Social engineering, phishing or physical attacks against Formudex or anyone associated with it.
  • Vulnerabilities in third-party services we use but do not operate, such as GitHub Pages and Google Workspace. Report these to the provider; tell us too if our configuration is the problem.
  • Automated scanner output, and missing security headers, email-authentication settings (SPF, DKIM, DMARC) or DNS records such as CAA, without demonstrated impact. GitHub Pages controls this site’s response headers. We read these reports but do not treat them as vulnerabilities.
  • Findings that require a compromised device, a modified client or physical access to a user’s unlocked machine.

We will keep this policy current as products are released.

Testing in good faith

If you make a good-faith effort to follow this policy, Formudex, LLC considers your research authorized and will not take legal action against you for it. If someone else does, we will make clear that your testing was authorized. This covers only systems Formudex controls. We cannot authorize testing of GitHub, Google or other providers, whose own policies apply.

Please test only against your own data and email, stop once you have shown the issue, do not send spoofed email to anyone but yourself, and give us reasonable time to fix a problem before you publish it. If you are unsure whether something is allowed, ask first.

What we will do

  • Acknowledge your report within a reasonable time.
  • Tell you whether we consider it in scope and how serious we think it is.
  • Tell you when it is fixed, or if we decide not to fix it and why.
  • Credit you by name or handle if we publish about the issue and you want credit, and not name you if you prefer not to be named.

We do not currently run a bug bounty or pay for reports. We handle reports as described in our privacy policy.

Last updated 27 September 2026.