Snapshot 19695
Normalized text
Scripts and page chrome removed; this is what change detection compares.
Vulnerability disclosure policy Coordinated disclosure Factory Labs welcomes good-faith vulnerability reports against any of our properties. Below is exactly what you can test, how to report, what you can expect from us, and the safe-harbor protection that covers your research. Report to security@factorylabs.ai Acknowledge ≤ 1 business day Critical fix ≤ 7 days target 01 Scope All of the following are in scope. If you are unsure whether a target is in scope, email security@factorylabs.ai before testing. In scope factorylabs.ai and all *.factorylabs.ai subdomains, including the marketing site, Trust Center, docs, and the customer app shell. The public CRM Factory product accessible after sign-in (any tenant you legitimately own or have written permission to test). Public APIs under /api/v1/* and /api/public/*. Mobile web clients and any first-party SDK published by Factory Labs. Authentication, multi-tenancy and authorization logic. Bugs that allow cross-tenant access are top priority. Out of scope Third-party SaaS we use (Vercel, Neon, Twilio, Resend, Anthropic, OpenAI, Deepgram, Stripe, …). Report those to the vendor; we're happy to triage on your behalf. Volumetric DoS / DDoS, brute force, traffic flooding. Social engineering, phishing of staff or customers, physical attacks. Missing security headers, weak TLS ciphers, or other cosmetic findings already mitigated by configuration unless you can demonstrate exploitability. Self-XSS, clickjacking on pages without sensitive actions, login/forgot-password username enumeration on endpoints that already rate-limit. Reports from automated scanners without manual validation. 02 Rules of engagement Don't access data you don't own. If you find a cross-tenant or privilege-escalation bug, stop at proof-of-concept. Do not enumerate other tenants' records. No destructive testing. No data exfiltration beyond what's needed to demonstrate impact, no creating durable footholds, no deletion or modification of data. Use your own test tenant. Sign up for a free trial and test there. If a bug requires upgrading to a paid plan, email us first and we'll provision a sandbox tenant. Keep it private. Don't disclose publicly until we've had a fair chance to fix. See “Disclosure timeline” below. Use the official channel. Send reports to security@factorylabs.ai. Do not file public GitHub issues, tweet about unpatched bugs, or DM the founders. 03 What you can expect from us Stage Target What happens Acknowledgment ≤ 1 business day A person confirms we received your report. Triage decision ≤ 5 business days We tell you the severity rating (Critical / High / Medium / Low) and whether the report is accepted. Fix: Critical ≤ 7 days Cross-tenant, RCE, full account takeover, or PII exfiltration. Hot-patched on production. Fix: High ≤ 30 days Authenticated privilege escalation, sensitive data exposure, auth bypass on narrow paths. Fix: Medium / Low ≤ 90 days Bundled into the next scheduled hardening cycle. Public disclosure 90 days from triage If the fix is shipped, we'll credit you here (with your permission). If not, we'll explain why and request an extension. 04 Safe harbor When you act in good faith and follow this policy, Factory Labs will: Not initiate legal action against you, including under the Computer Fraud and Abuse Act (CFAA), DMCA §1201, or anti-circumvention claims. Consider your testing activity authorized access for the purposes of computer-fraud and similar statutes. Help you navigate any third-party platform whose terms might otherwise be implicated. If at any point you're uncertain whether a particular piece of research is covered, email us first at security@factorylabs.ai and we'll respond before you proceed. This safe-harbor language is adapted from disclose.io. 05 How to report Send an email to security@factorylabs.ai with the following: Summary: one-line description of the issue and worst-case impact. Reproduction steps: ordered list, ideally with cURL commands, request IDs or video. Include the test tenant slug. Affected URL(s) / API endpoint(s). Suggested severity: your own rating; we'll re-triage. Disclosure preference: whether you want credit, want to remain anonymous, or are planning a public write-up (and when). PGP-encrypted reports are accepted. Fetch our public key at /.well-known/security.txt and reach out if you need a signed PGP key file. 06 Acknowledgments Researchers who help us improve our security posture in line with this policy will be credited below (with permission). We're a young company. Be the first. No public disclosures yet. Submit yours and we'll add you here. Policy version 1.0 · Last updated May 10, 2026 · Factory Labs Inc., 8 The Green Ste B, Dover, DE 19901