Trust → Responsible Disclosure

Find something? Tell us.

We don't punish researchers. If you find a security issue, we want to hear about it, fix it, and credit you.

Quick contact

Email: security@felarity.com

PGP: available on request, fingerprint published in /.well-known/security.txt

Acknowledgement: within 2 business days · Initial assessment: within 5 business days

What to include

What's in scope

What's out of scope

Rules of engagement (safe harbor)

If you act in good faith and follow these rules, we will not pursue civil or criminal action against you and we will work with you in good faith on disclosure.

Hall of thanks

Once we have valid disclosures to credit, this page will list them by name (or handle, if you prefer). We don't currently run a paid bounty program — we do offer swag and a public acknowledgement, and we treat researchers as the colleagues they are.

If you're stuck

For non-security issues, contact hello@felarity.com. For abuse, abuse@felarity.com. For legal, legal@felarity.com.