Where to report
Write to fragorstudios@gmail.com with the word Security in the subject line. It is our regular inbox and a person reads it.
If the report involves sensitive data, say so in the first message without attaching anything: we will set up an encrypted channel before you send it. [PGP key to be published]
What to include in the report
The exact address or the part of the site affected.
The steps to reproduce it, in order. A screenshot or a short video is worth more than three paragraphs.
What the flaw makes possible: reading other people's data, running code, bypassing a control.
The browser and operating system you tested on, with the approximate date and time.
How you want to be credited if we publish a thank you, or whether you prefer to stay anonymous.
What we promise you
We acknowledge receipt within 72 hours. If three days pass with no reply, send it again: the message got lost.
After that we tell you what we found when reviewing it, whether we are going to fix it and the estimated timeframe.
We will not take legal action or seek penalties against anyone who researches in good faith and respects this policy. Good faith means not touching third-party data beyond the minimum needed to demonstrate the flaw, not deleting or modifying anything, not disrupting the service, and not publishing the details before it is fixed.
We ask for ninety days to fix it before you make it public. If we need more, we will tell you and discuss it.
What is out of scope
Denial of service attacks, load testing and anything that degrades the service for other people.
Social engineering against us, our clients or our providers, and phishing campaigns.
Spam, mass messaging and abuse of the contact inbox.
Physical access to equipment, and attacks that require an already compromised machine or a browser that has not been updated in years.
Automated scanner output with no demonstrated impact: a missing header, a library one version behind, no SPF record on a domain that sends no email. If you have a concrete case that exploits it, tell us about that case.
Client sites we do not administer. Write to the site owner; if you let us know, we will make the introduction.
Rewards and credit
We do not run a bug bounty. We are a small studio and cannot pay for reports, and we would rather say so up front than waste your time.
What we do offer is public credit, with your name and a link, if you want it. If you would rather not appear anywhere, you will not.
Changes and questions
This policy may change; the date above says when it last did. It is a written commitment about how we will handle your report, not a contract and not legal advice.
If you are unsure whether something is in scope, ask before testing: fragorstudios@gmail.com.