How to report
Email hello@fowlguard.com with the word Security in the subject. Include:
- what you found and where, with the steps to reproduce it
- what an attacker could do with it
- how to reach you for follow-up questions
Please do not include other people's personal data in your report. If you had to see some to confirm the issue, tell us that instead.
What is in scope
- fowlguard.com and its public pages
- Sign-in, sign-up and account pages
- The customer console
- Fowlguard Connect on Windows, macOS and Linux
- Fowlguard Remote
Findings about a third-party service we use belong with that provider, but we would still like to know.
What we ask of you
- Test only against an organisation you created yourself. Never access, change or delete another customer's data.
- Do not run denial-of-service tests or anything that degrades the service for others.
- Do not use social engineering, phishing or physical attacks against our staff or customers.
- Give us a reasonable time to fix the issue before you publish anything about it.
What you can expect from us
- A reply confirming we received your report.
- An honest assessment of the issue and what we plan to do about it.
- Word from us when it is fixed.
We will not pursue legal action against research carried out in good faith within these guidelines.