Responsible Disclosure Policy
Effective and last updated: July 14, 2026
Purpose
The security of our systems and user data is our top priority. We appreciate the work of security researchers acting in good faith to identify and report potential vulnerabilities. This policy describes how to report vulnerabilities, what to expect from us, and the protections we offer in return.
Scope
This policy covers foundable.com, api.foundable.com, and Foundable-controlled services under *.foundable.com.
Customer-created apps, customer custom domains, and third-party provider systems are out of scope unless we give you written authorization. Please follow the applicable owner's disclosure policy.
In-scope vulnerabilities
We are interested in technical vulnerabilities such as:
- Cross-site scripting (XSS)
- Cross-site request forgery (CSRF)
- SQL injection
- Authentication or authorisation bypasses
- Privilege escalation
- Server-side request forgery (SSRF)
- Remote code execution
- Significant misconfigurations
Out-of-scope vulnerabilities
- General security best-practice findings without a working proof-of-concept
- Rate-limit or brute-force observations without demonstrated security impact
- Denial of service attacks
- Social engineering (including phishing)
- Physical attacks
- Clickjacking on pages with no sensitive actions
- Missing cookie flags without a demonstrable exploit or impact
- Widely publicised zero-day vulnerabilities with patches available for fewer than 30 days
AI-safety testing
You may report jailbreak, prompt-injection, cross-foundable context, or unsafe-agent-action findings to security@foundable.com. Test only against accounts, content, and connected services you control; do not cause messages, publications, purchases, or destructive actions for another person. Use the minimum testing needed to demonstrate the issue and follow the research guidelines below.
How to report
Email your findings to security@foundable.com. Please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce, including URLs and parameters
- Proof-of-concept code, screenshots, or screen recordings
- Your recommended fix, if any
Submit one vulnerability per report. The more detail you provide, the faster we can investigate and respond.
Research guidelines
When conducting security research, please:
- Test only for the purpose of identifying and reporting vulnerabilities
- Avoid accessing, modifying, or deleting data that is not your own
- Do not disrupt our services or degrade the experience for other users
- Do not exploit a vulnerability beyond what is minimally needed to prove it exists
- Coordinate disclosure timing with us before publishing
- Do not require payment as a condition of disclosure
What to expect from us
- We aim to acknowledge your report within 3 business days
- We will triage the report and share material updates when practical
- If you wish, we will credit you publicly when disclosing a fix
- We will not share your personal information without your consent unless required by law
Safe harbour
We consider research that follows this policy to be authorized and will not initiate legal action based solely on that research. This safe harbor does not bind third parties or law-enforcement agencies, authorize testing outside the scope above, or excuse violations of law, privacy, provider terms, extortion, or threats.
Changes to this policy
We may update this policy from time to time. The “Last updated” date at the top reflects the most recent revision. Vulnerabilities disclosed before an update remain subject to the policy in effect at the time of disclosure.
Questions about this document? security@foundable.com
Postal: Autono Labs, Inc. (operator of Foundable), 131 Continental Drive, Suite 305, Newark, DE 19713, USA. See /legal for our full set of policies.