Legal

Security & Vulnerability Disclosure

DRAFT. Prepared to support review; not legal advice. Complete the [bracketed] response times, PGP key, and disclosure window with [Ferrite Security] before publishing, and ensure the admin@ferritesec.com inbox is live.

Related: Acceptable use · Open-source notices · Export & sanctions · Data Processing Addendum

We build a security product, and we welcome good-faith security research. This policy explains how to report a vulnerability and what you can expect from us.

1. How to report

Email admin@ferritesec.com. Where possible, encrypt your report with our PGP key ([fingerprint / key URL to be published]). Please include: the affected version and edition, a description of the issue, reproduction steps or a proof of concept, and the potential impact.

2. Our commitments

  • We aim to acknowledge your report within [X] business days and to give a substantive response within [X] business days.
  • We will keep you informed as we investigate and remediate.
  • We will credit you in the advisory if you wish, once a fix is available.
  • Ferrite installs only cryptographically signed updates; we publish advisories for security-relevant fixes and maintain a software bill of materials (SBOM).

3. Safe harbor for good-faith research

We will not pursue legal action for research conducted in good faith and in accordance with this policy. To stay within it you must: only test systems and accounts you own or are authorized to test; avoid privacy violations, data destruction, and service degradation; not access, modify, or exfiltrate data that is not yours; and give us a reasonable opportunity to remediate before any public disclosure. This safe harbor does not extend to actions that violate applicable law.

4. Scope

In scope: the Ferrite desktop application, its update mechanism, and the ferritesec.com website. Out of scope: third-party components distributed with or used by Ferrite (for example the WinDivert driver and the Windows operating system), findings requiring physical access or social engineering, volumetric denial-of-service, and automated-scanner output without demonstrated impact.

5. Coordinated disclosure

We practice coordinated disclosure: please give us [X days] to remediate before publishing, and we will work with you on timing. A machine-readable version of this policy is published at /.well-known/security.txt.

← Back to home · Report: admin@ferritesec.com