Skip to content
Last updated 5 September 2026

Responsible disclosure

How to report a security issue, and what is in scope.

How to report

Email security@foundable.example with enough detail to reproduce the issue: affected endpoint, steps, impact and any proof-of-concept. We acknowledge reports and keep you updated while we work on them.

In scope

  • The Foundable web application.
  • The Foundable API.
  • Services we control on our own domains.

Out of scope

  • Applications and sites created by customers.
  • Customer custom domains.
  • Third-party providers and their systems.
  • Findings that require physical access, social engineering of our staff, or denial of service.
  • Reports produced solely by an automated scanner with no demonstrated impact.

Rules

  • Do not access, modify or delete data belonging to anyone else.
  • Use test accounts you control.
  • Do not run denial-of-service or high-volume automated testing.
  • Give us reasonable time to fix an issue before disclosing it publicly.

Recognition

We do not currently run a paid bounty. We do credit researchers who report in good faith and follow this policy, if they want to be named.

Start free with Ted.

Bring the messy version of the idea. Ted turns it into a first move, something real, and a way to see what people actually do — free to start, no card.

AI output needs your review. No income is promised or guaranteed.