Trust
Vulnerability Disclosure
How to report a security problem in Authfu, what we promise in return, and what is out of scope.
Last updated
01Our commitment
Safe harbor
We value clear reports from people who give us a fair chance to fix a problem. We will treat your report seriously, keep you informed, and work with you in good faith.
If you are unsure whether a planned test fits these rules, contact us first. We will answer as clearly as we can. Asking first is welcome, but it is not required for work already authorized above.
02How to report
Email security@authfu.com. A useful report tells us enough to reproduce the issue and understand why it matters.
Please include:
- what you found and which Authfu product or endpoint is affected;
- the steps needed to reproduce it;
- what an attacker could achieve; and
- any request, response, test account detail, or other material needed to verify it.
Send the report as plain text or Markdown. Video is welcome when it makes the behavior easier to see, but it is not a substitute for written reproduction steps.
Please use a concise subject line that identifies the affected product and the type of issue. Do not put credentials, session tokens, or another person’s data in the subject.
03What we commit to
We aim to meet these targets after receiving a report:
| Stage | Target |
|---|---|
| Acknowledgement | Within 2 business days |
| Initial assessment | Within 5 business days |
| Progress updates | At least every 10 business days while the report is open |
| Credit | In the release notes, if the reporter wants it |
These are targets we hold ourselves to, not aspirations. A complex issue may take longer to fix, but we keep communicating while it remains open.
There is no cash bounty today. A report is still eligible for credit when it leads to a security fix and the reporter wants to be named.
04Scope
In scope
authfu.app, including the console and identity service;authfu.com, the marketing and documentation site;authfu.link, the magic-link host;- the published Authfu API;
- the Authfu WordPress plugin; and
- the Authfu command-line tool.
Out of scope
- Anything a customer builds on top of Authfu. Report that issue to the customer who operates it.
- Third-party services, including Railway and Resend. Report vulnerabilities in those services to the relevant vendor.
- Physical attacks or social-engineering attacks against staff.
A customer integration may expose an Authfu vulnerability. If the underlying problem is in Authfu rather than the customer’s own code, report it to us.
05Rules of engagement
Keep testing controlled and proportionate:
- Test only with accounts you control.
- Do not access, modify, copy, or retain another person’s data. If you encounter it, stop testing and report the issue immediately.
- Do not perform denial-of-service attacks, load or stress tests, or automated scanning that degrades the service.
- Do not use social engineering, phish staff or users, or attempt physical intrusion.
- Do not publish the vulnerability before it is fixed. Coordinate disclosure timing with us.
We suggest 90 days as the default coordinated-disclosure window. That is a starting point, not a way to leave a reporter waiting in silence. We may agree on a different date based on severity, fix complexity, exploitation, and user risk.
Minimize the data and requests needed to prove the issue. A proof of concept should show impact without turning the test into an incident.
06What we consider low value
Some findings rarely lead to a meaningful fix without evidence of impact. Setting that expectation saves time on both sides. Examples include:
- missing security headers with no demonstrated impact;
- weak TLS cipher suites without a working exploit;
- automated-scanner output with no proof of exploitability;
- self-XSS;
- missing SPF or DMARC on domains that send no mail;
- rate-limit reports without a demonstrated consequence; and
- email enumeration claims that do not account for Authfu’s deliberately non-enumerating responses.
A report showing genuine security impact is always welcome, even if its title appears in this list. Show us the consequence rather than relying only on a category or scanner label.
07Encrypted reporting
We have not published a PGP key yet. If you need an encrypted channel, email security@authfu.com to arrange one before sending sensitive details.
Do not rely on a key or fingerprint found somewhere else unless we confirm it through an Authfu-controlled channel.