We welcome reports from security researchers and anyone else who finds a weakness in our website or products. If you believe you've found one, please tell us privately so we can fix it before it can be abused.
How to report
Email [email protected] with “Security” in the subject. Please include:
- what you found and where (URL, product, version or commit);
- steps to reproduce it, or a proof of concept;
- the impact you think it has;
- how you'd like to be credited, if at all.
Our machine-readable contact details are in /.well-known/security.txt.
Scope
In scope: fusionarcade.io and its subdomains, and the products in our portfolio (Chamber, Lifekeep, MapSight, Bridge, Forge OS).
Out of scope: denial-of-service testing, spam, social engineering or phishing of our team, physical attacks, and findings in third-party services we use (report those to the vendor).
What we ask
- Give us reasonable time to fix the issue before telling anyone else.
- Only access data you need to show the problem, never other people's data beyond that, and delete anything you obtained once you've reported it.
- Don't degrade our services or disrupt other users.
What we promise
- We'll acknowledge your report within five business days and keep you updated until it is resolved.
- We won't take legal action against research done in good faith under this policy.
- With your permission, we'll credit you once the fix is out.
No bug bounty yet. We don't currently pay rewards, but we're grateful for every report.