Scope
This policy covers www.fellowdata.com and the systems and products that Fellow Data operates. It does not cover third-party services that we use; please report issues in those services to their provider.
The following are out of scope:
- Findings from automated scanners without a demonstrated impact
- Missing best-practice settings without a demonstrated security impact
- Social engineering, phishing or physical attacks
- Denial-of-service attacks
How to report
Email info@fellowdata.com with the subject "Security vulnerability report". Please include:
- The affected product or URL
- A description of the vulnerability
- Steps to reproduce it
- Your assessment of its impact
- Supporting evidence, such as screenshots or logs
- Your contact information
Our security contact is also published at /.well-known/security.txt.
What not to do
When researching a vulnerability, do not:
- Access, modify or delete customer data, or any data that is not yours
- Perform destructive testing
- Run denial-of-service tests
- Social-engineer our employees or partners
- Keep access to a system after you have confirmed a vulnerability
- Exfiltrate data
Please do not disclose a vulnerability publicly until we have had a reasonable time to fix it.
What you can expect
We will acknowledge your report, investigate it and keep you informed of our progress. If you wish, we will credit you once the issue is fixed.
Good-faith research
If you act in good faith and follow this policy, we will treat your research as authorised and will not take legal action against you for it. This does not cover activity that breaks the law or harms our customers.