Responsible disclosure
We test other people's systems for a living. If you find a problem in ours, we want to hear about it, and we will treat you the way we would want to be treated.
Scope
This policy covers frontiercyber.app, its subdomains, and the infrastructure that serves them. Reports about RiskTrace or Frontier Verify are welcome at the same address and will be routed to the right team. Systems we assess or operate on behalf of clients are out of scope: they belong to the client and are covered by the client's own policies.
How to report
Email security@frontiercyber.com. Include enough for us to reproduce the issue: the affected URL or component, the steps you took, what you observed, and your assessment of impact. Screenshots, requests and responses help. If you want credit, tell us the name or handle to use. If you want to stay anonymous, that is fine too.
A machine-readable version of this contact is published at /.well-known/security.txt.
What we commit to
- We acknowledge your report within two business days.
- We triage it, tell you whether we can reproduce it and how we rate it, within five business days.
- We keep you informed as we fix it, and we tell you when the fix is live.
- We credit you on request once the issue is resolved, if you would like that.
- We do not take legal action against researchers who follow this policy.
We do not currently run a paid bounty program.
Safe harbour
Security research conducted in good faith and in accordance with this policy is authorized. We consider it to be authorized access under applicable Canadian law, we will not pursue or support legal action against you for it, and if a third party raises a legal action related to research that complied with this policy, we will make it known that your actions were authorized. If at any point you are unsure whether something is within this policy, stop and ask us first.
Rules
- Do not degrade service. No denial of service, no volumetric testing, no automated scanning at rates that affect availability.
- Do not access, modify or delete data that is not yours. If you encounter personal or client data, stop, record only what is needed to demonstrate the issue, and report it.
- Stop at the first evidence of a vulnerability. Do not pivot into other systems or escalate further than needed to prove impact.
- No social engineering of our staff or clients, no phishing, and no physical attempts on premises.
- Give us a reasonable time to fix the issue before any public disclosure. We aim for ninety days from your report, and we will agree a date with you if we need longer.
- Do not use the issue for anything other than demonstrating it to us.
Out of scope
The following are not vulnerabilities on their own and will be closed without action unless you demonstrate a real impact:
- Missing security headers, cookie flags or best-practice configuration without a demonstrated exploit.
- Clickjacking on pages with no sensitive actions.
- SPF, DKIM or DMARC configuration opinions without a demonstrated spoofing path.
- Version disclosure, software banners and informational findings.
- Rate limiting on forms that already have abuse controls.
- Reports from automated tools without analysis.
- Issues that require a compromised device, browser extension or physical access.
Contact
Security reports: security@frontiercyber.com.
Frontier Cyber, Vancouver, Canada.