Responsible disclosure

How to report a security vulnerability to us.

We welcome reports from security researchers. If you believe you have found a vulnerability in fastfde.ai, please tell us so we can fix it.

How to report

  • Email hello@fastfde.ai with “Security” in the subject, or use our contact form and choose “Security or vulnerability report”.
  • Describe the issue, the steps to reproduce it, and its likely impact. Do not include sensitive data you may have seen.
  • Our machine-readable contact details are in /.well-known/security.txt.

Scope

In scope: fastfde.ai and www.fastfde.ai. Out of scope: third-party services we use (report those to the provider), denial-of-service testing, social engineering, and physical attacks.

Rules of engagement

  • Test only against your own requests and data. Do not access, modify or delete data that is not yours.
  • Do not degrade the site for others. No load testing, no automated scanning at volume.
  • Give us reasonable time to fix an issue before disclosing it publicly.

Safe harbor

If you act in good faith and follow this policy, we will not pursue legal action against you for your research, and we will work with you to understand and resolve the issue.

What to expect

We aim to acknowledge reports within three business days and to keep you updated as we investigate. We do not currently run a paid bug bounty.