Legal
Report security concerns
Version 1.0 · Last updated 15 September 2026
Responsible disclosure and how to reach our security team.
1. We want to hear from you
If you found a security vulnerability in Firelent, thank you for looking — and for telling us instead of someone else. Report it to security@firelent.com, ideally with enough detail that we can reproduce it: affected endpoint or page, steps, impact, and a proof of concept if you have one. We read every report.
2. Scope
- firelent.com and the Firelent studio;
- our APIs and backend services (api.firelent.cloud);
- the publishing and preview infrastructure serving firelent.app sites;
- our mobile applications and the Telegram assistant.
Customer projects themselves are out of scope — a bug in a website someone built with Firelent belongs to its operator, unless the flaw is in the platform underneath (in which case: very much in scope, tell us). Third-party services we integrate with have their own programs.
3. Rules of engagement
- access only what is needed to demonstrate the issue — never other people’s data at scale; if you hit personal data, stop, note it, report it;
- no denial-of-service, spam floods or physical intrusion;
- no social engineering of our team or our users;
- no public disclosure before we have had a reasonable chance to fix — we will agree on a timeline with you and we will not sit on it;
- do not demand payment as a condition of disclosure.
4. Safe harbor
Research conducted in good faith within these rules is authorized access in our book: we will not pursue legal action against you for it, and if a third party does, we will make it known that your research was authorized. This does not cover actions outside the rules above.
5. Our commitments
- acknowledgment within 3 business days;
- an honest assessment of severity and a fix timeline, with updates until it is resolved;
- credit for your find, if you want it, once fixed;
- no bug-bounty program yet — if that changes, this page will say so first.
6. Usually out of scope
Reports we generally cannot act on: missing security headers without demonstrated impact, SPF/DMARC configuration opinions, clickjacking on pages without sensitive actions, version disclosure, and automated scanner output without a shown vulnerability. When in doubt, send it anyway — a short honest “probably minor” note beats silence.