Trust Center
Vulnerability Disclosure Policy
๐
Effective: 1 June 2025
๐ Last updated: 20 May 2026
We welcome responsible disclosure. If you have found a security vulnerability in Fragiliti, thank you. We want to hear from you. This policy explains how to report it safely and what you can expect from us.
1. Our Commitment to You
Fragiliti commits to the following when you report a vulnerability in good faith:
- We will not take legal action against you for discovering and responsibly reporting a vulnerability.
- We will acknowledge your report within 48 hours.
- We will keep you informed about our progress, at least every 7 days until resolved.
- We will fix confirmed vulnerabilities as promptly as reasonably possible based on severity.
- We will credit you in our acknowledgements page (if you wish).
We ask that you act in good faith and follow the guidelines in this policy. In return, we will treat you with the same respect.
2. Scope - What to Report
The following are in scope:
- fragiliti.com - main website
- app.fragiliti.com - the Platform application
- Any API endpoint used by the Platform
- Fragiliti mobile apps (if released)
The following are out of scope:
- Third-party services we use (AWS, Stripe, Razorpay, PostHog) - report these to them directly
- Issues that only affect browsers no longer supported by the vendor
- Social engineering attacks on Fragiliti employees
- Physical attacks
- Theoretical vulnerabilities with no practical impact
- Rate limiting or spam issues (unless they lead to data exposure)
3. What We're Most Interested In
| Priority | Type |
| ๐ด Critical | Authentication bypass, unauthorised access to other customers' data, remote code execution, SQL injection leading to data exposure |
| ๐ High | Privilege escalation, mass data exposure, stored XSS in authenticated areas, broken access controls |
| ๐ก Medium | Reflected XSS, CSRF on sensitive actions, insecure direct object references |
| ๐ข Low | Clickjacking without sensitive actions, missing headers, minor information disclosure |
4. Rules - Please Follow These
You may:
- Test on your own accounts
- Use automated tools with caution (no DoS)
- Report issues that you discover incidentally during normal use
You must not:
- Access, download, or modify other customers' data
- Perform denial-of-service attacks
- Spam or send mass requests that degrade the Platform for others
- Publicly disclose the vulnerability before we have had a chance to fix it (see Section 5)
- Use the vulnerability for personal gain or to cause harm
- Conduct social engineering or phishing on Fragiliti staff
5. Coordinated Disclosure
We follow a coordinated disclosure model:
- You report the vulnerability to us privately.
- We investigate, confirm, and fix it.
- We agree on a public disclosure timeline, typically 90 days from your initial report, or sooner once the fix is deployed.
- You may publish your findings after the fix is live or after 90 days, whichever comes first.
If we need more than 90 days, we will explain why and request an extension.
6. How to Report
Please send your report to:
Email: contact@fragiliti.com
Subject line: "Security Vulnerability Disclosure"
In your report, please include:
- Description of the vulnerability and its potential impact
- Steps to reproduce (as detailed as possible)
- Any proof-of-concept code or screenshots (please blur or mask any real user data)
- Your name or alias (if you want credit)
- Whether you would like to be publicly credited
Encryption: If your report contains highly sensitive details, please mention this in your first email and we will arrange a secure channel for the full disclosure.
7. Our Response Timeline
| Step | Timeframe |
| Acknowledge receipt of your report | Within 48 hours |
| Confirm whether the issue is valid | Within 7 days |
| Provide an estimated fix timeline | Within 14 days of confirmation |
| Deploy fix (critical issues) | Within 72 hours of confirmation |
| Deploy fix (high issues) | Within 14 days |
| Deploy fix (medium/low issues) | Within 30โ90 days |
| Coordinated public disclosure | 90 days from initial report (or sooner) |
8. Safe Harbour
Fragiliti will not take civil or criminal action against security researchers who:
- Follow the guidelines in this policy
- Act in good faith to avoid privacy violations, service disruption, and harm to others
- Report the vulnerability to us before any public disclosure
- Do not exploit the vulnerability beyond what is necessary to demonstrate it
We consider responsible vulnerability research to be a valuable contribution to internet security.