Responsible Disclosure
Help us investigate security issues safely.
This policy should provide a clear good-faith reporting route without authorizing destructive testing.
01Report a vulnerability
- To be confirmed
- Form
- To be confirmed
- Pgp
- To be confirmed
02Out of scope / prohibited testing
- Third-party systems not controlled by Fuchsius
- Social engineering
- Physical attacks
- Denial of service
- Spam
- Testing that materially degrades service
- Accessing/modifying other users' data beyond the minimum proof required
03Good-faith guidelines
- Avoid privacy violations and data destruction
- Do not exploit beyond minimum proof
- Do not disrupt service
- Report promptly with reproduction steps
- Allow reasonable remediation time before disclosure
- Comply with applicable law
04Safe harbor
REPLACE_WITH_COUNSEL_APPROVED_SAFE_HARBOR_LANGUAGE
05Response targets
- Acknowledgement
- To be confirmed
- Triage
- To be confirmed
- Updates
- To be confirmed
- Rule
- Do not publish response targets that security operations cannot consistently support.
This document is a draft framework provided for review. It is not legal advice, and it must be confirmed against actual Fuchsius operations and applicable law before publication.