Skip to content

Vulnerability disclosure

Effective date:
11 September 2026
Last updated:

Fellow Data encourages responsible reporting of suspected security vulnerabilities. If you believe you have found one in a Fellow Data system, please tell us so we can investigate and fix it.

Scope

This policy covers www.fellowdata.com and the systems and products that Fellow Data operates. It does not cover third-party services that we use; please report issues in those services to their provider.

The following are out of scope:

  • Findings from automated scanners without a demonstrated impact
  • Missing best-practice settings without a demonstrated security impact
  • Social engineering, phishing or physical attacks
  • Denial-of-service attacks

How to report

Email info@fellowdata.com with the subject "Security vulnerability report". Please include:

  • The affected product or URL
  • A description of the vulnerability
  • Steps to reproduce it
  • Your assessment of its impact
  • Supporting evidence, such as screenshots or logs
  • Your contact information

Our security contact is also published at /.well-known/security.txt.

What not to do

When researching a vulnerability, do not:

  • Access, modify or delete customer data, or any data that is not yours
  • Perform destructive testing
  • Run denial-of-service tests
  • Social-engineer our employees or partners
  • Keep access to a system after you have confirmed a vulnerability
  • Exfiltrate data

Please do not disclose a vulnerability publicly until we have had a reasonable time to fix it.

What you can expect

We will acknowledge your report, investigate it and keep you informed of our progress. If you wish, we will credit you once the issue is fixed.

Good-faith research

If you act in good faith and follow this policy, we will treat your research as authorised and will not take legal action against you for it. This does not cover activity that breaks the law or harms our customers.