Security
Responsible Disclosure Policy
The information on this page is intended for security researchers interested in
reporting security vulnerabilities to the FloydHub security team.
If you are a customer seeking support related to your account, billing, or site
content, please reach out to our customer support at
[email protected].
If you believe you have discovered a security vulnerability on FloydHub, we
strongly encourage you to inform us as quickly as possible and to not disclose
the vulnerability publicly until it is fixed. We appreciate your assistance,
and we review all reports and will do our best to address the issue in a
timely fashion. To encourage responsible disclosure, FloydHub will not bring
a lawsuit against you or ask law enforcement to investigate you if we
determine that a disclosure meets the following guidelines.
Responsible Disclosure Guidelines
- Notify FloydHub and provide us details of the vulnerability. Please provide us a reasonable time period (at least 90 days) to address the issue before public disclosure.
- Provide an appropriate level of detail on the vulnerability to allow us to identify and reproduce the issue. Detail should include target URLs, request/response pairs, screenshots, and/or other information.
- We will confirm your email and evaluate the validity and reproducibility of the issue. For valid issues, we will work to fix the issue and keep you appraised of progress.
- Make a reasonable effort to avoid service disruption (e.g. DoS), privacy issues (i.e. accessing a FloydHub customer’s data), and data destruction when performing vulnerability research.
- Do not request compensation for security vulnerability reports either from FloydHub or external vulnerability marketplaces.
- Do not phish or social engineer employees or customers of FloydHub.
- Do not run automated scanning tools and send us the output without confirming the issue is present. Security tools often output false positives that should be confirmed by the reporter.
How to Report a Security Vulnerability
Security vulnerabilities may be reported via email to [email protected]. If
you do not want to be publicly thanked on our Security Hall of Fame page
(or elsewhere), please let us know that you want your submission to be
confidential in your report email. We are also happy to accept anonymous vulnerability reports.
The validity of a vulnerability will be judged at the sole discretion of FloydHub.
Contacting Us
Questions regarding this Security Policy should be directed to [email protected].