Third Party Index

Snapshot 19695

Document
Security advisories
URL
https://factorylabs.ai/security/disclosure
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
211590 bytes
SHA-256 (raw)
89d31d7b6133d1639723c4132b0e813acbf6a8496017a2c3e077ce3e65077afe
SHA-256 (normalized text)
59e4727a8322c08e55759c98592af873b648465cf9f678500b88142c6e88a67f

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Vulnerability disclosure policy
Coordinated disclosure
Factory Labs welcomes good-faith vulnerability reports against any of our properties. Below is exactly what you can test, how to report, what you can expect from us, and the safe-harbor protection that covers your research.
Report to
security@factorylabs.ai
Acknowledge
≤ 1 business day
Critical fix
≤ 7 days target
01
Scope
All of the following are in scope. If you are unsure whether a target is in scope, email security@factorylabs.ai before testing.
In scope
factorylabs.ai and all *.factorylabs.ai subdomains, including the marketing site, Trust Center, docs, and the customer app shell.
The public CRM Factory product accessible after sign-in (any tenant you legitimately own or have written permission to test).
Public APIs under /api/v1/* and /api/public/*.
Mobile web clients and any first-party SDK published by Factory Labs.
Authentication, multi-tenancy and authorization logic. Bugs that allow cross-tenant access are top priority.
Out of scope
Third-party SaaS we use (Vercel, Neon, Twilio, Resend, Anthropic, OpenAI, Deepgram, Stripe, …). Report those to the vendor; we're happy to triage on your behalf.
Volumetric DoS / DDoS, brute force, traffic flooding.
Social engineering, phishing of staff or customers, physical attacks.
Missing security headers, weak TLS ciphers, or other cosmetic findings already mitigated by configuration unless you can demonstrate exploitability.
Self-XSS, clickjacking on pages without sensitive actions, login/forgot-password username enumeration on endpoints that already rate-limit.
Reports from automated scanners without manual validation.
02
Rules of engagement
Don't access data you don't own. If you find a cross-tenant or privilege-escalation bug, stop at proof-of-concept. Do not enumerate other tenants' records.
No destructive testing. No data exfiltration beyond what's needed to demonstrate impact, no creating durable footholds, no deletion or modification of data.
Use your own test tenant. Sign up for a free trial and test there. If a bug requires upgrading to a paid plan, email us first and we'll provision a sandbox tenant.
Keep it private. Don't disclose publicly until we've had a fair chance to fix. See “Disclosure timeline” below.
Use the official channel. Send reports to security@factorylabs.ai. Do not file public GitHub issues, tweet about unpatched bugs, or DM the founders.
03
What you can expect from us
Stage	Target	What happens
Acknowledgment	≤ 1 business day	A person confirms we received your report.
Triage decision	≤ 5 business days	We tell you the severity rating (Critical / High / Medium / Low) and whether the report is accepted.
Fix: Critical	≤ 7 days	Cross-tenant, RCE, full account takeover, or PII exfiltration. Hot-patched on production.
Fix: High	≤ 30 days	Authenticated privilege escalation, sensitive data exposure, auth bypass on narrow paths.
Fix: Medium / Low	≤ 90 days	Bundled into the next scheduled hardening cycle.
Public disclosure	90 days from triage	If the fix is shipped, we'll credit you here (with your permission). If not, we'll explain why and request an extension.
04
Safe harbor
When you act in good faith and follow this policy, Factory Labs will:
Not initiate legal action against you, including under the Computer Fraud and Abuse Act (CFAA), DMCA §1201, or anti-circumvention claims.
Consider your testing activity authorized access for the purposes of computer-fraud and similar statutes.
Help you navigate any third-party platform whose terms might otherwise be implicated.
If at any point you're uncertain whether a particular piece of research is covered, email us first at security@factorylabs.ai and we'll respond before you proceed. This safe-harbor language is adapted from disclose.io.
05
How to report
Send an email to security@factorylabs.ai with the following:
Summary: one-line description of the issue and worst-case impact.
Reproduction steps: ordered list, ideally with cURL commands, request IDs or video. Include the test tenant slug.
Affected URL(s) / API endpoint(s).
Suggested severity: your own rating; we'll re-triage.
Disclosure preference: whether you want credit, want to remain anonymous, or are planning a public write-up (and when).
PGP-encrypted reports are accepted. Fetch our public key at /.well-known/security.txt and reach out if you need a signed PGP key file.
06
Acknowledgments
Researchers who help us improve our security posture in line with this policy will be credited below (with permission). We're a young company. Be the first.
No public disclosures yet. Submit yours and we'll add you here.
Policy version 1.0 · Last updated May 10, 2026 · Factory Labs Inc., 8 The Green Ste B, Dover, DE 19901