Responsible disclosure.
Found a weakness in Unforged? Tell us privately and give us the chance to fix it before anyone else hears about it.
Email us
Write to [email protected] with “Security” in the subject. Please don’t open a public issue or share the details until we’ve fixed it.
What to include
- What you found and where: the page, the endpoint or the host.
- Steps to reproduce, with any requests, payloads or screenshots.
- What an attacker could do with it, as you understand it.
- How to reach you, and the name to thank if you’d like one.
Scope
In scope
- unforged.ai and its pages, including the dashboard
- api.unforged.sh and the regional hosts under it
- Webhooks we send and the signatures on them
Out of scope
- Social engineering of our staff or customers
- Denial of service, load or volume testing
- Physical attacks on offices or equipment
- Third-party services we use, unless the flaw is in how we use them
- Reports from automated scanners without a demonstrated impact
Test only against your own account and your own data. Never access, change or delete anyone else’s, and stop as soon as you’ve shown the problem.
Safe harbour
Act in good faith, stay within this policy and give us reasonable time to fix what you found, and we won’t take legal action against you or ask anyone else to. Not sure whether something is allowed? Ask us first.
What happens next
- We acknowledge your report as soon as we can.
- We keep you told what we find and when it’s fixed.
- We credit you once it’s fixed, if you’d like.
We don’t run a paid bounty programme.
Machine-readable contact details are in security.txt. How we protect your data is on Security.