Trust Center
Responsible disclosure
We welcome good-faith reports that help us protect customers and systems. This page is the authoritative policy; it is also referenced from security.txt and Company Information.
In scope
- farqadcloud.com and its subdomains
- Systems we operate for customers, only with that customer's written authorization
Out of scope
- Third-party services we use (email hosting, payment processing, our hosting provider): report those to the vendor concerned
- Denial-of-service, volumetric or brute-force testing
- Social engineering, phishing, or physical attacks against people or premises
- Findings that require a compromised device or account to exploit
- Missing best-practice headers or configuration without a demonstrated impact
Rules of engagement
- Do not destroy data, degrade service, or access data beyond what proves the issue
- Do not include real personal data of third parties in proof-of-concept payloads
- Stop and report as soon as you can demonstrate the vulnerability
- Give us reasonable time to remediate before any public disclosure
What to expect from us
- Acknowledgement within 3 business days
- A status update at least every 14 days until resolution
- Coordinated disclosure: we aim to remediate within 90 days and will agree a publication date with you; credit is given if you wish
- No bug bounty is offered at this time
Safe harbor
Research conducted in good faith, within this scope and these rules, is authorized. We will not pursue or support legal action against you for it, and we will not report you to law enforcement for accidental, good-faith violations of this policy.
Get in touch by email
Include the affected URL/system, a description with proof-of-concept steps, and your contact details. Encrypted reports are welcome; ask for a public key by email first. We acknowledge within 3 business days.
security@farqadcloud.com