Security

Responsible disclosure.

How to report a vulnerability to us, and what you can expect in return.

We welcome reports from security researchers and anyone else who finds a weakness in our website or products. If you believe you've found one, please tell us privately so we can fix it before it can be abused.

How to report

Email [email protected] with “Security” in the subject. Please include:

  • what you found and where (URL, product, version or commit);
  • steps to reproduce it, or a proof of concept;
  • the impact you think it has;
  • how you'd like to be credited, if at all.

Our machine-readable contact details are in /.well-known/security.txt.

Scope

In scope: fusionarcade.io and its subdomains, and the products in our portfolio (Chamber, Lifekeep, MapSight, Bridge, Forge OS).

Out of scope: denial-of-service testing, spam, social engineering or phishing of our team, physical attacks, and findings in third-party services we use (report those to the vendor).

What we ask

  • Give us reasonable time to fix the issue before telling anyone else.
  • Only access data you need to show the problem, never other people's data beyond that, and delete anything you obtained once you've reported it.
  • Don't degrade our services or disrupt other users.

What we promise

  • We'll acknowledge your report within five business days and keep you updated until it is resolved.
  • We won't take legal action against research done in good faith under this policy.
  • With your permission, we'll credit you once the fix is out.

No bug bounty yet. We don't currently pay rewards, but we're grateful for every report.