How to report
Email contact@foldox.com. Please include:
- the website and the URL affected
- steps to reproduce the problem
- what an attacker could do
- a proof of concept, if you have one
- how to reach you
Don’t include other people’s personal data. Our machine-readable contact is in security.txt.
Scope
In scope: foldox.com and the public websites of the apps we operate:
hiy.ai describes how it handles security on its trust page.
Out of scope:
- anything not listed as in scope above
- services run by other companies (report those to them)
- social engineering or phishing of our staff
- physical attacks
- denial of service or load testing
- automated scanner output without a working exploit
- missing headers or best-practice notes with no shown impact
Rules for testing
- Use only your own accounts and test data.
- If you reach anyone else’s data, stop, don’t keep it, and tell us.
- No denial of service, spam or social engineering.
- Don’t run scans that slow the service down.
Please give us reasonable time to fix an issue before you publish it.
Good-faith research
We welcome good-faith reports. We won’t treat research as abuse when it stays within the rules on this page. We can’t promise that we will not take legal action, and this page does not give permission to break the law.
What we’ll do
We aim to reply within five working days. We will try to keep you updated and to tell you when it’s fixed.
Rewards
We don’t run a paid bug bounty.
How we protect foldox.com
- HTTPS, with HSTS.
- A Content Security Policy and other security headers that limit where the site can load content from.
- Spam protection on the contact form.
This list covers foldox.com only. It makes no claims about the apps we operate; see their own sites for that.