← Iron Forge

Vulnerability disclosure policy

Iron Forge · Version 1.0 · Effective 24 July 2026

Security research done in good faith makes the Service safer for everyone, and we welcome it. This Vulnerability Disclosure Policy (the "Policy") tells you how to report a security vulnerability to us, what you may and may not do while looking for one, and what you can expect from us in return. It is our standing written authorisation for good-faith security research within the scope and conditions below — the authorisation the Acceptable Use Policy § 2.3 refers to.

This Policy is not an invitation to test the accounts or data of real users, and it is not a bug bounty. It is a promise that if you find something and tell us responsibly, we will fix it, treat you with respect, and not come after you for helping.

Contents

  1. Scope
  2. How to report
  3. The rules — what good-faith research means
  4. What you can expect from us
  5. Safe harbour
  6. Coordinated disclosure
  7. No bounty
  8. Changes
  9. Contact

1. Scope

In scope:

Out of scope:

If you are unsure whether something is in scope, ask first at the address in § 2.

2. How to report

Email security@iron-forge.app (or, if that address is unavailable, ironforge.admin@gmail.com with "SECURITY" in the subject line). Please include, as far as you can:

Please report in confidence and give us a reasonable opportunity to fix the issue before you publish anything (see § 5).

3. The rules — what good-faith research means

Your research is authorised under this Policy only if you:

4. What you can expect from us

5. Safe harbour

If you make a good-faith effort to follow this Policy, then to the fullest extent of our power:

This safe harbour cannot bind third parties or prosecutors, and it does not apply to research that breaks the § 3 rules — in particular anything that harms real users or their data.

6. Coordinated disclosure

We ask for a coordinated disclosure window of 90 days from your report (or longer by agreement if a fix is genuinely complex; shorter if we ship the fix sooner). After the fix is live — or the window lapses without good cause on our side — you are welcome to publish your findings; we'd appreciate seeing the text first, purely to check no user data or unfixed issue is exposed. We publish significant fixed vulnerabilities ourselves where users need to know or act.

7. No bounty

We do not run a paid bug-bounty programme, and this Policy creates no entitlement to payment. We may, entirely at our discretion, thank a researcher whose report materially helped (for example with complimentary subscription time) — the same goodwill basis as feature requests under the Terms of Service § 10.

8. Changes

We may update this Policy as the Service grows or the law changes; the version and date above will change when we do. Research conducted under the version in force when you started it keeps that version's protection.

9. Contact

Vulnerability reports: security@iron-forge.app (fallback: ironforge.admin@gmail.com, subject "SECURITY"). Anything else: ironforge.admin@gmail.com.

Version 1.0 — first final release, effective 24 July 2026. Added to the legal pack as document #10, satisfying Annex I Part II (5)–(6) of the EU Cyber Resilience Act. The machine-readable contact is published at /.well-known/security.txt (RFC 9116).