Responsible Disclosure Policy

Effective date: March 21, 2026. Last updated: October 3, 2026.

We take security seriously

FactorCat is an MFA platform, so security is the product. If you've found a vulnerability, we want to hear about it. We appreciate the work of security researchers and are committed to working with you to verify and address issues promptly.

Researchers who have reported issues to us are credited on our security acknowledgements page.

How to report

Preferred: If you have a FactorCat account, use the in-app feedback form (Settings > Feedback) and select "Security issue" as the category. This ensures your report is routed directly to the security team with your account context attached.

Fallback: If you don't have an account or prefer a form, use our contact page and select "Security disclosure."

Please include as much detail as possible: steps to reproduce, affected components, potential impact, and any proof-of-concept code or screenshots. The more detail you provide, the faster we can triage and fix the issue.

What's in scope

What's out of scope

Response commitments

Stage Timeline
Acknowledgement Within 48 hours
Initial triage Within 5 business days
Status update At least every 10 business days while open
Fix or mitigation Severity-dependent. Critical issues are prioritized immediately.

Safe harbor

We consider security research conducted in accordance with this policy to be authorized. We will not pursue legal action against researchers who:

If legal action is initiated by a third party against you for activities conducted in accordance with this policy, we will take steps to make it known that your actions were authorized.

Recognition

We believe in recognizing the people who help keep FactorCat secure. For valid reports we credit you on our security acknowledgements page. Tell us how you would like to appear and we will use exactly that. If you do not tell us, the entry is credited as Anonymous, and we will not publish the address you reported from. You can add, change, or remove your details at any time, before or after the entry goes up.

Paste this into your report and there is nothing further to ask you:

Credit as:            (a name, a handle, a company, or Anonymous)
Link or email:        (optional, and it does not have to be the address you
                       are writing from)

We do not currently offer monetary bounties. As FactorCat grows, we intend to formalize a paid bug bounty program. For now, we offer our sincere thanks and public recognition.

Disclosure guidelines

Contact

Contact form