Reporting a vulnerability
If you have found a security problem in this website or in software we publish, we want to hear about it, and we would rather hear it from you than from an incident.
01How to report
Email contact@forgesynapse.com with enough detail to reproduce the issue: what you did, what happened, and what you expected. A proof of concept helps. If you would prefer to encrypt the report, say so and we will arrange it.
This address is also published in our security.txt, at /.well-known/security.txt.
02What to expect
We aim to acknowledge a report within three working days and to tell you what we intend to do about it within ten. If a fix takes longer than that, we will say why rather than go quiet.
We are a small company and we do not run a paid bug bounty. What we do offer is a straight answer, credit if you want it, and no legal threat for reporting in good faith.
03Testing we ask you not to do
Please do not run denial-of-service tests, do not attempt to access data belonging to anyone else, do not modify or destroy data, and do not use social engineering against people. Automated scanning that degrades the service for other visitors is not useful to either of us.
04Scope
This site, and the software we publish under the ForgeSynapse organisation on GitHub. Issues in third-party platforms we link to should be reported to those platforms.
This website is a static build with no database, no server-side execution and no user accounts, which removes whole categories of vulnerability but does not remove all of them. Reports about the security headers, the content security policy or the deployment configuration are welcome.
These pages were prepared in-house and are not a substitute for legal advice. If anything here conflicts with a signed agreement, the agreement prevails.