Legal

Report security concerns

Version 1.0 · Last updated 15 September 2026

Responsible disclosure and how to reach our security team.

1. We want to hear from you

If you found a security vulnerability in Firelent, thank you for looking — and for telling us instead of someone else. Report it to security@firelent.com, ideally with enough detail that we can reproduce it: affected endpoint or page, steps, impact, and a proof of concept if you have one. We read every report.

2. Scope

  • firelent.com and the Firelent studio;
  • our APIs and backend services (api.firelent.cloud);
  • the publishing and preview infrastructure serving firelent.app sites;
  • our mobile applications and the Telegram assistant.

Customer projects themselves are out of scope — a bug in a website someone built with Firelent belongs to its operator, unless the flaw is in the platform underneath (in which case: very much in scope, tell us). Third-party services we integrate with have their own programs.

3. Rules of engagement

  • access only what is needed to demonstrate the issue — never other people’s data at scale; if you hit personal data, stop, note it, report it;
  • no denial-of-service, spam floods or physical intrusion;
  • no social engineering of our team or our users;
  • no public disclosure before we have had a reasonable chance to fix — we will agree on a timeline with you and we will not sit on it;
  • do not demand payment as a condition of disclosure.

4. Safe harbor

Research conducted in good faith within these rules is authorized access in our book: we will not pursue legal action against you for it, and if a third party does, we will make it known that your research was authorized. This does not cover actions outside the rules above.

5. Our commitments

  • acknowledgment within 3 business days;
  • an honest assessment of severity and a fix timeline, with updates until it is resolved;
  • credit for your find, if you want it, once fixed;
  • no bug-bounty program yet — if that changes, this page will say so first.

6. Usually out of scope

Reports we generally cannot act on: missing security headers without demonstrated impact, SPF/DMARC configuration opinions, clickjacking on pages without sensitive actions, version disclosure, and automated scanner output without a shown vulnerability. When in doubt, send it anyway — a short honest “probably minor” note beats silence.