Responsible disclosure · reviewed 2026-07-28

Reporting a vulnerability

If you have found a security issue in Fortoxa, this page tells you where to send it, what you may and may not test, what Fortoxa commits to, and — plainly — what it has not committed to yet.

Contact

Where to send it.

Security mailbox

[email protected]

Include reproduction steps, the affected URL or asset, the impact, and logs or screenshots where it is safe to share them. Say whether you want credit after remediation.

This is a monitored mailbox, not a forwarding alias — the platform delivers its own automated security alerts to the same address.

Response times: no commitment has been set

Fortoxa has not published a response-time commitment for security reports, because it does not yet have the on-call staffing to guarantee one. Reports are read and worked in severity order. If you need a guaranteed acknowledgement window before you will disclose, say so in your first email and Fortoxa will agree one with you directly.

An earlier version of this page advertised a 24-hour acknowledgement and a 72-hour triage target. Nothing backed those numbers, so they have been withdrawn rather than restated.

Scope

What you may test.

In scope

  • fortoxa.com
  • The Fortoxa web application and its API
  • The Fortoxa agent and its event-ingest endpoints

Out of scope

  • Any tenant or workspace that is not your own
  • Third-party services Fortoxa uses — report those to the provider (see the subprocessor list)
  • Findings that require physical access to a device or office

Allowed

  • Testing against your own tenant or workspace only
  • Non-destructive proof-of-concept, stopping at the point impact is demonstrated
  • Reporting with enough detail for Fortoxa to reproduce and validate the issue

Not allowed

  • Denial of service, volumetric testing, or load generation
  • Social engineering Fortoxa staff, customers or partners
  • Testing against other customers' tenants
  • Public disclosure before a fix has shipped and a timeline has been agreed
  • Destructive actions, persistence, data exfiltration, or tampering with other users' data

Process

What happens after you report.

  1. 01

    Email the security mailbox with a clear title, the affected route or asset, the impact, steps to reproduce, and proof-of-concept detail.

  2. 02

    Fortoxa confirms receipt, validates scope, and records the finding.

  3. 03

    Fortoxa works the fix and may ask you to retest before it is closed.

  4. 04

    Public disclosure and researcher credit are coordinated after remediation, where you want them.

Safe harbour

Fortoxa will not pursue legal action over good-faith research conducted within this policy. Avoid privacy violations, service disruption, destructive testing and persistence. If you encounter data that is not yours, stop and report it.

Credit and CVEs

Fortoxa can credit you after remediation if you want it. Fortoxa is not a CVE Numbering Authority; where a report needs CVE coordination it will be routed to the relevant upstream vendor or CNA.

Not a researcher? For account or general security questions use the contact form, or read the security posture page.