Authfu

Trust

Vulnerability Disclosure

How to report a security problem in Authfu, what we promise in return, and what is out of scope.

Last updated

01Our commitment

Safe harbor

Security research conducted in good faith and within these rules is authorized by Authfu. We will not pursue legal action against you, or ask your employer, hosting provider, or another intermediary to take action against you, for that research. If a third party brings legal action over research that followed these rules, we will make it known that we authorized your work.

We value clear reports from people who give us a fair chance to fix a problem. We will treat your report seriously, keep you informed, and work with you in good faith.

If you are unsure whether a planned test fits these rules, contact us first. We will answer as clearly as we can. Asking first is welcome, but it is not required for work already authorized above.

02How to report

Email security@authfu.com. A useful report tells us enough to reproduce the issue and understand why it matters.

Please include:

  • what you found and which Authfu product or endpoint is affected;
  • the steps needed to reproduce it;
  • what an attacker could achieve; and
  • any request, response, test account detail, or other material needed to verify it.

Send the report as plain text or Markdown. Video is welcome when it makes the behavior easier to see, but it is not a substitute for written reproduction steps.

Please use a concise subject line that identifies the affected product and the type of issue. Do not put credentials, session tokens, or another person’s data in the subject.

03What we commit to

We aim to meet these targets after receiving a report:

StageTarget
AcknowledgementWithin 2 business days
Initial assessmentWithin 5 business days
Progress updatesAt least every 10 business days while the report is open
CreditIn the release notes, if the reporter wants it

These are targets we hold ourselves to, not aspirations. A complex issue may take longer to fix, but we keep communicating while it remains open.

There is no cash bounty today. A report is still eligible for credit when it leads to a security fix and the reporter wants to be named.

04Scope

In scope

  • authfu.app, including the console and identity service;
  • authfu.com, the marketing and documentation site;
  • authfu.link, the magic-link host;
  • the published Authfu API;
  • the Authfu WordPress plugin; and
  • the Authfu command-line tool.

Out of scope

  • Anything a customer builds on top of Authfu. Report that issue to the customer who operates it.
  • Third-party services, including Railway and Resend. Report vulnerabilities in those services to the relevant vendor.
  • Physical attacks or social-engineering attacks against staff.

A customer integration may expose an Authfu vulnerability. If the underlying problem is in Authfu rather than the customer’s own code, report it to us.

05Rules of engagement

Keep testing controlled and proportionate:

  • Test only with accounts you control.
  • Do not access, modify, copy, or retain another person’s data. If you encounter it, stop testing and report the issue immediately.
  • Do not perform denial-of-service attacks, load or stress tests, or automated scanning that degrades the service.
  • Do not use social engineering, phish staff or users, or attempt physical intrusion.
  • Do not publish the vulnerability before it is fixed. Coordinate disclosure timing with us.

We suggest 90 days as the default coordinated-disclosure window. That is a starting point, not a way to leave a reporter waiting in silence. We may agree on a different date based on severity, fix complexity, exploitation, and user risk.

Minimize the data and requests needed to prove the issue. A proof of concept should show impact without turning the test into an incident.

06What we consider low value

Some findings rarely lead to a meaningful fix without evidence of impact. Setting that expectation saves time on both sides. Examples include:

  • missing security headers with no demonstrated impact;
  • weak TLS cipher suites without a working exploit;
  • automated-scanner output with no proof of exploitability;
  • self-XSS;
  • missing SPF or DMARC on domains that send no mail;
  • rate-limit reports without a demonstrated consequence; and
  • email enumeration claims that do not account for Authfu’s deliberately non-enumerating responses.

A report showing genuine security impact is always welcome, even if its title appears in this list. Show us the consequence rather than relying only on a category or scanner label.

07Encrypted reporting

We have not published a PGP key yet. If you need an encrypted channel, email security@authfu.com to arrange one before sending sensitive details.

Do not rely on a key or fingerprint found somewhere else unless we confirm it through an Authfu-controlled channel.

08Contact

Report security issues to security@authfu.com. Automated tools can also find our current disclosure details at authfu.com/.well-known/security.txt.