Skip to content

Security

Report a security vulnerability responsibly

The security of our systems and services is important to us. If you discover a potential security vulnerability in a website, application or service operated by ForgeOne, we ask you to report it responsibly.

ForgeOne Logo auf Laptop

What should a report include?

Please provide us with sufficient information so that we can understand and assess the issue.

  • a brief description of the potential vulnerability
  • the affected system, product or URL
  • reproducible steps
  • an assessment of the potential impact
  • screenshots or technical details, if helpful

Responsible disclosure

Please conduct investigations in a way that does not adversely affect systems, data or users. In particular, we ask you to avoid the following actions:

  • accessing other people's data that is not required for verification
  • modifying, deleting or downloading other people's data
  • affecting the availability of our systems or services
  • social engineering, phishing or deception of employees and customers
  • automated tests with high load or disruptive behavior

Please do not publish details of a potential vulnerability before we have had the opportunity to review the report and implement appropriate measures.

What happens after a report?

We review incoming security reports and will contact you if we require further information. Depending on the type and scope of the report, the technical analysis may take varying amounts of time.

No public bug bounty program

ForgeOne does not currently operate a public bug bounty program. Compensation for security reports is not guaranteed.

For general support requests or questions about products and services, please use our regular contact and support channels.

security.txt

For automated tools and security researchers, we also provide our machine-readable contact information as security.txt.

Canonical URL

https://forgeone.solutions/.well-known/security.txt

security.txt öffnen ↗