← Security

Responsible disclosure.

Found a weakness in Unforged? Tell us privately and give us the chance to fix it before anyone else hears about it.

How to report

Email us

Write to with “Security” in the subject. Please don’t open a public issue or share the details until we’ve fixed it.

What to include

  • What you found and where: the page, the endpoint or the host.
  • Steps to reproduce, with any requests, payloads or screenshots.
  • What an attacker could do with it, as you understand it.
  • How to reach you, and the name to thank if you’d like one.

Scope

In scope

  • unforged.ai and its pages, including the dashboard
  • api.unforged.sh and the regional hosts under it
  • Webhooks we send and the signatures on them

Out of scope

  • Social engineering of our staff or customers
  • Denial of service, load or volume testing
  • Physical attacks on offices or equipment
  • Third-party services we use, unless the flaw is in how we use them
  • Reports from automated scanners without a demonstrated impact

Test only against your own account and your own data. Never access, change or delete anyone else’s, and stop as soon as you’ve shown the problem.

Good faith

Safe harbour

Act in good faith, stay within this policy and give us reasonable time to fix what you found, and we won’t take legal action against you or ask anyone else to. Not sure whether something is allowed? Ask us first.

What happens next

  1. We acknowledge your report as soon as we can.
  2. We keep you told what we find and when it’s fixed.
  3. We credit you once it’s fixed, if you’d like.

We don’t run a paid bounty programme.

Machine-readable contact details are in . How we protect your data is on .