Security Acknowledgements

Researchers who reported a security issue to FactorCat and helped us fix it.

FactorCat is an MFA platform, so security is the product. The people listed here found something we had missed, told us privately, and gave us the time to fix it. We are grateful to all of them.

If you have found something, our responsible disclosure policy explains how to report it and what happens next.

How credit works

You tell us how you would like to appear and we use exactly that. It can be a name, a handle, a company, or Anonymous. You can include an optional link to a profile or site, or an email address you have chosen for this page.

Anonymous is the default. If you have not told us how you want to be credited, your entry is published as Anonymous with no link. We will not guess, and we will never publish the address you reported from unless you have specifically asked us to use it here.

The description of what you found, and of how we resolved it, is written by us. It is deliberately light on mechanism so that reading this page does not hand anyone a map of our systems.

Changing or removing your entry

You can add, change, or remove your details at any time, before or after your entry goes up. That includes adding a name or link later if you were originally credited as Anonymous, and asking to be removed entirely with no explanation needed.

Use our contact form and select "Security disclosure", or reply to the thread where you reported the issue.

Eligibility

An entry is created when a report is:

We do not currently offer monetary bounties. As FactorCat grows, we intend to formalize a paid bug bounty program. For now, we offer our sincere thanks and public recognition.