Skip to main content

Security

Responsible disclosure and security practices

Reporting a Vulnerability

We take security seriously. If you discover a vulnerability in Formatho, we appreciate responsible disclosure and will make every effort to acknowledge and address your report.

Report to:

[email protected]

Or use our security.txt (RFC 9116):

https://formatho.com/.well-known/security.txt

Scope

In scope

  • • formatho.com and all subdomains (qa.formatho.com)
  • • XSS, CSRF, SQL injection, SSRF vulnerabilities
  • • Authentication/authorization bypasses
  • • Data exposure (if any tool inadvertently transmits data)
  • • Content Security Policy bypasses
  • • Subdomain takeover

Out of scope

  • • Rate limiting or brute force (report, but low priority)
  • • Reports from automated scanners without PoC
  • • Social engineering attacks
  • • Physical security
  • • DoS/DDoS (do not test)

Our Security Practices

HTTPS enforced

TLS 1.2+ with HSTS preload

CSP headers

Strict Content-Security-Policy

Zero cookies

No tracking cookies to hijack

Client-side only

No server-side data to breach

security.txt

RFC 9116 disclosure contact

Regular updates

Dependencies kept current

Safe Harbor

We will not pursue legal action against researchers who make a good-faith effort to comply with this policy:

  • Use only the minimum testing necessary to verify the vulnerability
  • Avoid privacy violations, data destruction, and degradation of user experience
  • Give us reasonable time to fix the issue before public disclosure
  • Do not access, modify, or delete data that does not belong to you

Response Timeline

24 hrs

Acknowledgment of your report

72 hrs

Initial assessment and severity classification

7 days

Fix deployment for critical issues

30 days

Resolution or documented timeline for complex issues

Recognition

With your permission, we will acknowledge your contribution (name/handle and link) once the vulnerability is fixed. We do not currently offer monetary bounties.