Security
Responsible disclosure and security practices
Reporting a Vulnerability
We take security seriously. If you discover a vulnerability in Formatho, we appreciate responsible disclosure and will make every effort to acknowledge and address your report.
Report to:
[email protected]Or use our security.txt (RFC 9116):
https://formatho.com/.well-known/security.txtScope
In scope
- • formatho.com and all subdomains (qa.formatho.com)
- • XSS, CSRF, SQL injection, SSRF vulnerabilities
- • Authentication/authorization bypasses
- • Data exposure (if any tool inadvertently transmits data)
- • Content Security Policy bypasses
- • Subdomain takeover
Out of scope
- • Rate limiting or brute force (report, but low priority)
- • Reports from automated scanners without PoC
- • Social engineering attacks
- • Physical security
- • DoS/DDoS (do not test)
Our Security Practices
HTTPS enforced
TLS 1.2+ with HSTS preload
CSP headers
Strict Content-Security-Policy
Zero cookies
No tracking cookies to hijack
Client-side only
No server-side data to breach
security.txt
RFC 9116 disclosure contact
Regular updates
Dependencies kept current
Safe Harbor
We will not pursue legal action against researchers who make a good-faith effort to comply with this policy:
- Use only the minimum testing necessary to verify the vulnerability
- Avoid privacy violations, data destruction, and degradation of user experience
- Give us reasonable time to fix the issue before public disclosure
- Do not access, modify, or delete data that does not belong to you
Response Timeline
Acknowledgment of your report
Initial assessment and severity classification
Fix deployment for critical issues
Resolution or documented timeline for complex issues
Recognition
With your permission, we will acknowledge your contribution (name/handle and link) once the vulnerability is fixed. We do not currently offer monetary bounties.