Security & Vulnerability Disclosure Policy

FastBound is committed to maintaining the security and privacy of our users, customers, and partners. We welcome responsible disclosure of security vulnerabilities and will work with security researchers to verify and address legitimate issues.

Reporting a Security Issue

If you believe you have discovered a security vulnerability affecting FastBound systems or services, please report it as soon as possible.

Preferred reporting method:

  • Email: security@fastbound.com

Please include:

  • A clear description of the vulnerability
  • Steps to reproduce or proof of concept
  • Affected systems, endpoints, or URLs
  • Any relevant logs, screenshots, or artifacts
  • Your contact information (optional)

Sensitive reports may be encrypted using FastBound’s Security Team’s PGP public key.

Scope

In Scope

  • FastBound-owned domains and subdomains
  • FastBound web applications and APIs
  • Authentication, authorization, and access-control issues
  • Server-side vulnerabilities and data exposure

Out of Scope

  • Denial-of-service (DoS/DDoS) attacks
  • Social engineering or phishing attacks
  • Physical security issues
  • Vulnerabilities in third-party services not under FastBound’s control
  • Issues requiring unrealistic or non-production configurations

Safe Harbor

FastBound considers security research conducted in accordance with this policy to be authorized.

FastBound will not pursue legal action against individuals who:

  • Act in good faith
  • Avoid privacy violations and data destruction
  • Do not disrupt service availability
  • Do not access or modify user data beyond what is necessary to demonstrate impact
  • Provide FastBound reasonable time to investigate and remediate reported issues

This safe harbor applies only to activities conducted within the scope of this policy.

Disclosure, Recognition, and Compensation

FastBound does not operate a formal bug bounty program and does not publish a reward or compensation schedule.

FastBound values responsible security research and recognizes that meaningful vulnerability discovery and disclosure may require significant time, expertise, and effort.

After a vulnerability has been responsibly disclosed, validated, and determined to be within scope, FastBound may, at its sole discretion, choose to offer compensation. Such compensation, when offered, is intended to reflect services rendered, and may take the form of a short-term consulting engagement related to:

  • Vulnerability discovery and analysis
  • Impact assessment and exploitability research
  • Clear and responsible disclosure
  • Optional collaboration on remediation or verification of fixes

Compensation decisions are made on a case-by-case basis, are not guaranteed, and are subject to separate agreement. Submission of a vulnerability report does not create any entitlement, expectation, or obligation of compensation.

Findings Not Eligible for Compensation

FastBound does not provide compensation for reports that consist primarily of:

  • Automated scan output without demonstrated, material impact
  • Low-risk or theoretical issues without clear exploitability
  • Best-practice recommendations without a specific vulnerability
  • Issues previously known to FastBound or already under remediation
  • Vulnerabilities in third-party services or dependencies not under FastBound’s control
  • Reports that are incomplete, unclear, or not reproducible

Reports must demonstrate original analysis and real-world security impact to be considered.

FastBound reserves the right to close reports that do not meet these criteria without further response.

Data Handling & Confidentiality

Any information obtained during security research must be:

  • Kept confidential
  • Used solely for the purpose of vulnerability reporting
  • Deleted once the issue has been resolved

Public disclosure of vulnerabilities without coordination is not permitted.

Questions

Questions regarding this policy or whether specific testing activities are permitted may be directed to security@fastbound.com.