Security
If you have found a security problem in something Formudex runs, we want to hear about it. This page is our vulnerability disclosure policy: what we cover, how to report and what we will do.
Reporting
Where to send it, and what to include
Email security@formudex.io. A machine-readable version of this contact information is published at /.well-known/security.txt.
A useful report includes:
- The affected host, URL or service.
- What the issue is and why it matters, in your own words.
- Steps to reproduce it, with any request or response detail that helps.
- What you did and did not do while testing.
- How you would like to be credited, if you want credit.
Please write in English. If you need to send something sensitive and would prefer to encrypt it, say so in your first message and we will send you a key.
Scope
What is covered
In scope: formudex.io and its subdomains, and any service that Formudex, LLC operates and that is reachable from the public internet.
Out of scope:
- Volumetric denial-of-service, load testing and anything that degrades service for other people.
- Social engineering, phishing or physical attacks against Formudex or anyone associated with it.
- Vulnerabilities in third-party services we use rather than operate. Report those to the provider; tell us as well if our configuration is the problem.
- Reports that consist only of automated scanner output, missing security headers or general hardening suggestions with no demonstrated impact. We will still read them, but they are not treated as vulnerabilities.
- Findings that require a compromised device, a modified client or physical access to a user's unlocked machine.
This site is static and has no accounts, no forms and no server-side code of ours, so the realistic surface here is small. That will change as products are released, and this policy will be kept current.
Our response
What we will do
- Acknowledge your report within a reasonable time.
- Tell you whether we consider it in scope, and what we think its impact is.
- Keep you informed while we work on it, and tell you when it is fixed.
- Credit you by name or handle when we publish anything about the issue, if you want that. We will not name you if you would rather stay anonymous.
Formudex does not currently run a bug bounty and does not offer payment for reports.