Security & Vulnerability Disclosure
Related: Acceptable use · Open-source notices · Export & sanctions · Data Processing Addendum
We build a security product, and we welcome good-faith security research. This policy explains how to report a vulnerability and what you can expect from us.
1. How to report
Email admin@ferritesec.com. Where possible, encrypt your report with our PGP key ([fingerprint / key URL to be published]). Please include: the affected version and edition, a description of the issue, reproduction steps or a proof of concept, and the potential impact.
2. Our commitments
- We aim to acknowledge your report within [X] business days and to give a substantive response within [X] business days.
- We will keep you informed as we investigate and remediate.
- We will credit you in the advisory if you wish, once a fix is available.
- Ferrite installs only cryptographically signed updates; we publish advisories for security-relevant fixes and maintain a software bill of materials (SBOM).
3. Safe harbor for good-faith research
We will not pursue legal action for research conducted in good faith and in accordance with this policy. To stay within it you must: only test systems and accounts you own or are authorized to test; avoid privacy violations, data destruction, and service degradation; not access, modify, or exfiltrate data that is not yours; and give us a reasonable opportunity to remediate before any public disclosure. This safe harbor does not extend to actions that violate applicable law.
4. Scope
In scope: the Ferrite desktop application, its update mechanism, and the ferritesec.com website. Out of scope: third-party components distributed with or used by Ferrite (for example the WinDivert driver and the Windows operating system), findings requiring physical access or social engineering, volumetric denial-of-service, and automated-scanner output without demonstrated impact.
5. Coordinated disclosure
We practice coordinated disclosure: please give us [X days] to remediate before publishing, and we will work with you on timing. A machine-readable version of this policy is published at /.well-known/security.txt.
← Back to home · Report: admin@ferritesec.com