Trust Center

Vulnerability Disclosure Policy

๐Ÿ“… Effective: 1 June 2025 ๐Ÿ”„ Last updated: 20 May 2026
We welcome responsible disclosure. If you have found a security vulnerability in Fragiliti, thank you. We want to hear from you. This policy explains how to report it safely and what you can expect from us.

1. Our Commitment to You

Fragiliti commits to the following when you report a vulnerability in good faith:

We ask that you act in good faith and follow the guidelines in this policy. In return, we will treat you with the same respect.

2. Scope - What to Report

The following are in scope:

The following are out of scope:

3. What We're Most Interested In

PriorityType
๐Ÿ”ด CriticalAuthentication bypass, unauthorised access to other customers' data, remote code execution, SQL injection leading to data exposure
๐ŸŸ  HighPrivilege escalation, mass data exposure, stored XSS in authenticated areas, broken access controls
๐ŸŸก MediumReflected XSS, CSRF on sensitive actions, insecure direct object references
๐ŸŸข LowClickjacking without sensitive actions, missing headers, minor information disclosure

4. Rules - Please Follow These

You may:
  • Test on your own accounts
  • Use automated tools with caution (no DoS)
  • Report issues that you discover incidentally during normal use
You must not:
  • Access, download, or modify other customers' data
  • Perform denial-of-service attacks
  • Spam or send mass requests that degrade the Platform for others
  • Publicly disclose the vulnerability before we have had a chance to fix it (see Section 5)
  • Use the vulnerability for personal gain or to cause harm
  • Conduct social engineering or phishing on Fragiliti staff

5. Coordinated Disclosure

We follow a coordinated disclosure model:

  1. You report the vulnerability to us privately.
  2. We investigate, confirm, and fix it.
  3. We agree on a public disclosure timeline, typically 90 days from your initial report, or sooner once the fix is deployed.
  4. You may publish your findings after the fix is live or after 90 days, whichever comes first.

If we need more than 90 days, we will explain why and request an extension.

6. How to Report

Please send your report to:

Email: contact@fragiliti.com
Subject line: "Security Vulnerability Disclosure"

In your report, please include:

Encryption: If your report contains highly sensitive details, please mention this in your first email and we will arrange a secure channel for the full disclosure.

7. Our Response Timeline

StepTimeframe
Acknowledge receipt of your reportWithin 48 hours
Confirm whether the issue is validWithin 7 days
Provide an estimated fix timelineWithin 14 days of confirmation
Deploy fix (critical issues)Within 72 hours of confirmation
Deploy fix (high issues)Within 14 days
Deploy fix (medium/low issues)Within 30โ€“90 days
Coordinated public disclosure90 days from initial report (or sooner)

8. Safe Harbour

Fragiliti will not take civil or criminal action against security researchers who:

We consider responsible vulnerability research to be a valuable contribution to internet security.