Security

Vulnerability Disclosure Policy

We take security seriously. If you've discovered a vulnerability, we want to hear from you.

Scope

This policy applies to all services operated by Fast Cyber Defense, including:

  • fastcyberdefense.com and all subdomains
  • Client portal and API endpoints
  • Mobile applications (if applicable)

How to Report

Send your report to [email protected]. Include:

Description of the vulnerability
Steps to reproduce
Potential impact
Any proof-of-concept code or screenshots

Our Commitment

Within 24 hours

Acknowledge receipt of your report

Within 5 business days

Initial assessment and severity classification

Within 90 days

Remediation of confirmed vulnerabilities

Upon fix

Notification and optional public credit (with your permission)

Guidelines

When conducting security research, please:

  • Do not access, modify, or delete data belonging to other users
  • Do not perform denial-of-service attacks
  • Do not conduct social engineering or phishing against our staff
  • Provide sufficient time for remediation before public disclosure
  • Act in good faith β€” we will not pursue legal action for responsible disclosure

Safe Harbor

We consider security research conducted consistent with this policy to be authorized. We will not initiate legal action against researchers who follow these guidelines. We ask that you make a good faith effort to avoid privacy violations, data destruction, and service disruption.