Skip to content

Responsible Disclosure Policy

Version 1.0 — Last updated: June 17, 2026

Download PDF

1. Introduction

At FactoryNerve, the security of our platform and the trust of our customers are our top priorities. We recognise the valuable role that the security research community plays in helping us maintain a high security posture. This Responsible Disclosure Policy outlines our commitment to working with researchers who identify and report potential security vulnerabilities in our platform.

We encourage security researchers to report any vulnerabilities they discover in our systems responsibly. We pledge to acknowledge, investigate, and remediate verified reports in a timely manner, and to treat researchers with respect and transparency throughout the process.

2. Scope

This policy applies to the following systems and services operated by FactoryNerve:

  • The FactoryNerve web application (app.FactoryNerve and all subdomains under FactoryNerve)
  • FactoryNerve public API endpoints (api.FactoryNerve)
  • Official FactoryNerve mobile applications
  • Authentication and identity systems integrated with the platform

Third-party services, customer-hosted instances, and systems not explicitly listed above are outside the scope of this policy.

3. Submission Guidelines

To report a security vulnerability, please email us at:

security.factorynerve.online@redvortexorg.mePGP fingerprint: D4E9 F2C1 8A7B 3E5F 91C0 2B6D 7A3E 9F81 C4D2 E5F6

When submitting a report, please include:

  • A clear description of the vulnerability and its potential impact
  • Steps to reproduce the issue, including proof-of-concept code (if applicable)
  • The affected URL, endpoint, component, or version
  • Your preferred contact information for follow-up
  • Any relevant screenshots, logs, or network traffic captures

Please do not include personally identifiable information (PII) of other users in your proof-of-concept. If user data is necessary to demonstrate the issue, use your own test accounts.

4. Safe Harbor

Safe Harbor. FactoryNerve considers security research conducted in accordance with this policy to be:

  • Authorised and lawful under applicable computer fraud and abuse laws
  • Not a violation of our Acceptable Use Policy or Terms of Service
  • Exempt from any anti-circumvention provisions in our agreements

If legal action is initiated by a third party against a researcher for activities conducted in good faith and in compliance with this policy, FactoryNerve will take steps to clarify that the activities were authorised.

To qualify for safe harbor protections, researchers must:

  • Share the vulnerability report exclusively with FactoryNerve and not disclose it publicly until we have resolved the issue and granted permission
  • Not exploit the vulnerability beyond what is necessary to demonstrate the issue
  • Not access, modify, or delete data that does not belong to them
  • Act in good faith to avoid privacy violations, data destruction, and service disruption
  • Provide reasonable time for FactoryNerve to respond and remediate before any public disclosure

5. Bounty Program

FactoryNerve operates a vulnerability bounty program to recognise and reward researchers who help us improve our security. Bounties are awarded at our discretion based on the severity and quality of the report.

SeverityDescriptionReward
CriticalRemote code execution, SQL injection with data exfiltration, authentication bypass, privilege escalation to admin$2,000 – $5,000
HighCross-site scripting (stored), server-side request forgery, IDOR with sensitive data access, business logic flaws leading to data loss$500 – $2,000
MediumCross-site scripting (reflected), CSRF on state-changing actions, subdomain takeover, information disclosure of non-critical data$100 – $500
LowMinor information leaks, missing security headers, version disclosure, clickjacking on non-sensitive pagesRecognition only

All rewards are paid via bug bounty platform, bank transfer, or equivalent. Duplicate reports are eligible only for the first complete submission. Researchers must comply with applicable tax laws in their jurisdiction.

6. Our Commitments

When you report a vulnerability to us, we commit to:

  • Acknowledge receipt of your report within 3 business days
  • Evaluate and triage the report within 10 business days
  • Remediate verified vulnerabilities based on severity: Critical (7 days), High (14 days), Medium (30 days), Low (90 days)
  • Communicate progress updates at least once per week during remediation
  • Credit the researcher in our security acknowledgements (with permission)
  • Disclose vulnerability details after remediation, coordinated with the researcher

If remediation will take longer than the target timeline, we will provide a detailed explanation and an updated estimated completion date.

7. Out of Scope

The following activities and findings are explicitly outside the scope of this policy and are not eligible for bounties:

×Denial-of-service (DoS/DDoS) attacks
×Physical security attacks on FactoryNerve facilities or personnel
×Social engineering of FactoryNerve employees, contractors, or users
×Attacks on third-party services not operated by FactoryNerve
×Rate-limiting bypass or brute-force attacks on authentication endpoints
×Self-XSS or issues requiring user interaction with attacker-controlled input
×Previously reported vulnerabilities that have been triaged
×TLS cipher suite analysis or certificate transparency issues
×Content spoofing without a demonstrated security impact
×Presence of autocomplete attributes on non-sensitive forms

8. Contact

All vulnerability reports and security-related inquiries should be directed to:

Security Team: security.factorynerve.online@redvortexorg.me

PGP Key Fingerprint: D4E9 F2C1 8A7B 3E5F 91C0 2B6D 7A3E 9F81 C4D2 E5F6

For non-security inquiries, please visit our Contact page.