Reporting vulnerabilities
📌 This article is for security researchers only. If you are a Front customer with questions about security, contact Front Support.
Overview
Data security is Front’s top priority, and Front believes that working with skilled security researchers can identify weaknesses in any technology. If you believe you've found a security vulnerability in Front’s service or one of its apps, please notify us; we will work with you to resolve the issue promptly.
Disclosure policy
- Let us know as soon as possible when you’ve discovered a potential vulnerability by emailing us at security@frontapp.com.
- Provide us a reasonable amount of time to resolve the issue before disclosing it to the public or a third party. We aim to resolve critical issues within one week of disclosure.
- Make a good faith effort to avoid violating privacy, destroying data, or interrupting or degrading the Front service. Please only interact with accounts you own or for which you have explicit permission from the account holder.
Exclusions
While researching, we’d like you to refrain from:
- Denial of service
- Spamming
- Social engineering or phishing of FrontApp employees or contractors
- Any attacks against Front’s physical property or data centers
Thank you for helping to keep Front and our users safe!
Changes to these guidelines
We may revise these guidelines from time to time. The most current version of the guidelines will be available in this article.
Contact
Front is always open to feedback, questions, and suggestions. If you would like to talk to us, please feel free to contact us or follow us on Twitter at @FrontApp.