Responsible Disclosure

Help us investigate security issues safely.

This policy should provide a clear good-faith reporting route without authorizing destructive testing.

01Report a vulnerability

Email
To be confirmed
Form
To be confirmed
Pgp
To be confirmed

02Out of scope / prohibited testing

  • Third-party systems not controlled by Fuchsius
  • Social engineering
  • Physical attacks
  • Denial of service
  • Spam
  • Testing that materially degrades service
  • Accessing/modifying other users' data beyond the minimum proof required

03Good-faith guidelines

  • Avoid privacy violations and data destruction
  • Do not exploit beyond minimum proof
  • Do not disrupt service
  • Report promptly with reproduction steps
  • Allow reasonable remediation time before disclosure
  • Comply with applicable law

04Safe harbor

REPLACE_WITH_COUNSEL_APPROVED_SAFE_HARBOR_LANGUAGE

05Response targets

Acknowledgement
To be confirmed
Triage
To be confirmed
Updates
To be confirmed
Rule
Do not publish response targets that security operations cannot consistently support.

This document is a draft framework provided for review. It is not legal advice, and it must be confirmed against actual Fuchsius operations and applicable law before publication.