Responsible Disclosure Policy
Version 1.0 — Last updated: June 17, 2026
1. Introduction
At FactoryNerve, the security of our platform and the trust of our customers are our top priorities. We recognise the valuable role that the security research community plays in helping us maintain a high security posture. This Responsible Disclosure Policy outlines our commitment to working with researchers who identify and report potential security vulnerabilities in our platform.
We encourage security researchers to report any vulnerabilities they discover in our systems responsibly. We pledge to acknowledge, investigate, and remediate verified reports in a timely manner, and to treat researchers with respect and transparency throughout the process.
2. Scope
This policy applies to the following systems and services operated by FactoryNerve:
- The FactoryNerve web application (app.FactoryNerve and all subdomains under FactoryNerve)
- FactoryNerve public API endpoints (api.FactoryNerve)
- Official FactoryNerve mobile applications
- Authentication and identity systems integrated with the platform
Third-party services, customer-hosted instances, and systems not explicitly listed above are outside the scope of this policy.
3. Submission Guidelines
To report a security vulnerability, please email us at:
security.factorynerve.online@redvortexorg.me — PGP fingerprint: D4E9 F2C1 8A7B 3E5F 91C0 2B6D 7A3E 9F81 C4D2 E5F6
When submitting a report, please include:
- A clear description of the vulnerability and its potential impact
- Steps to reproduce the issue, including proof-of-concept code (if applicable)
- The affected URL, endpoint, component, or version
- Your preferred contact information for follow-up
- Any relevant screenshots, logs, or network traffic captures
Please do not include personally identifiable information (PII) of other users in your proof-of-concept. If user data is necessary to demonstrate the issue, use your own test accounts.
4. Safe Harbor
Safe Harbor. FactoryNerve considers security research conducted in accordance with this policy to be:
- Authorised and lawful under applicable computer fraud and abuse laws
- Not a violation of our Acceptable Use Policy or Terms of Service
- Exempt from any anti-circumvention provisions in our agreements
If legal action is initiated by a third party against a researcher for activities conducted in good faith and in compliance with this policy, FactoryNerve will take steps to clarify that the activities were authorised.
To qualify for safe harbor protections, researchers must:
- Share the vulnerability report exclusively with FactoryNerve and not disclose it publicly until we have resolved the issue and granted permission
- Not exploit the vulnerability beyond what is necessary to demonstrate the issue
- Not access, modify, or delete data that does not belong to them
- Act in good faith to avoid privacy violations, data destruction, and service disruption
- Provide reasonable time for FactoryNerve to respond and remediate before any public disclosure
5. Bounty Program
FactoryNerve operates a vulnerability bounty program to recognise and reward researchers who help us improve our security. Bounties are awarded at our discretion based on the severity and quality of the report.
| Severity | Description | Reward |
|---|---|---|
| Critical | Remote code execution, SQL injection with data exfiltration, authentication bypass, privilege escalation to admin | $2,000 – $5,000 |
| High | Cross-site scripting (stored), server-side request forgery, IDOR with sensitive data access, business logic flaws leading to data loss | $500 – $2,000 |
| Medium | Cross-site scripting (reflected), CSRF on state-changing actions, subdomain takeover, information disclosure of non-critical data | $100 – $500 |
| Low | Minor information leaks, missing security headers, version disclosure, clickjacking on non-sensitive pages | Recognition only |
All rewards are paid via bug bounty platform, bank transfer, or equivalent. Duplicate reports are eligible only for the first complete submission. Researchers must comply with applicable tax laws in their jurisdiction.
6. Our Commitments
When you report a vulnerability to us, we commit to:
- Acknowledge receipt of your report within 3 business days
- Evaluate and triage the report within 10 business days
- Remediate verified vulnerabilities based on severity: Critical (7 days), High (14 days), Medium (30 days), Low (90 days)
- Communicate progress updates at least once per week during remediation
- Credit the researcher in our security acknowledgements (with permission)
- Disclose vulnerability details after remediation, coordinated with the researcher
If remediation will take longer than the target timeline, we will provide a detailed explanation and an updated estimated completion date.
7. Out of Scope
The following activities and findings are explicitly outside the scope of this policy and are not eligible for bounties:
8. Contact
All vulnerability reports and security-related inquiries should be directed to:
Security Team: security.factorynerve.online@redvortexorg.me
PGP Key Fingerprint: D4E9 F2C1 8A7B 3E5F 91C0 2B6D 7A3E 9F81 C4D2 E5F6
For non-security inquiries, please visit our Contact page.