Skip to main content


Vulnerability Disclosure Policy for f12.biz

## Introduction

We at f12.biz take the security of our users and infrastructure seriously. We welcome and encourage the responsible disclosure of security vulnerabilities.

If you discover a vulnerability, we ask that you report it directly to us so that we can take appropriate action. We are committed to investigating all legitimate reports and resolving the issues as quickly as possible.


Reporting a Vulnerability

Please send detailed reports of potential vulnerabilities to:

📧 Email: security@f12.biz
🔐 PGP Key: available here

Please include the following in your report:

  • Description of the vulnerability
  • Steps to reproduce
  • Potential impact
  • Any supporting materials (logs, screenshots, PoC code)

Guidelines for Researchers

We ask that you:

  • Do not exploit the vulnerability beyond what is necessary to demonstrate the issue.
  • Avoid actions that could impact other users (e.g., DoS attacks, access to private data).
  • Do not publicly disclose the vulnerability before we have had a reasonable opportunity to address it.
  • Operate in good faith and comply with applicable laws.

What You Can Expect From Us

If you report a vulnerability according to this policy, we will:

  • Acknowledge your report within 5 business days.
  • Provide a status update at least once every 10 business days.
  • Treat your report confidentially and not pursue legal action.
  • Attribute credit to you (if desired) after the issue is resolved.
  • Strive to resolve confirmed vulnerabilities within 30 days.

Scope

The following domains and services are in scope:

Out-of-scope:

  • Third-party services not controlled by f12.biz
  • Social media accounts or marketing platforms

Hall of Fame

We may maintain a public thank-you list to acknowledge those who help improve our security posture.


Contact

To report a vulnerability:


Effective Date

This policy is effective as of August 4, 2025.