← Iron Forge
Vulnerability disclosure policy
Iron Forge · Version 1.0 · Effective 24 July 2026
Security research done in good faith makes the Service safer for everyone, and we welcome it. This Vulnerability Disclosure Policy (the "Policy") tells you how to report a security vulnerability to us, what you may and may not do while looking for one, and what you can expect from us in return. It is our standing written authorisation for good-faith security research within the scope and conditions below — the authorisation the Acceptable Use Policy § 2.3 refers to.
This Policy is not an invitation to test the accounts or data of real users, and it is not a bug bounty. It is a promise that if you find something and tell us responsibly, we will fix it, treat you with respect, and not come after you for helping.
1. Scope
In scope:
- The Iron Forge app — the PWA at web.iron-forge.app and the Android app (
app.ironforge on Google Play);
- The public site at iron-forge.app;
- The Iron Forge Pro console at pro.iron-forge.app;
- The API at api.iron-forge.app, including the public API described in the API Developer Terms.
Out of scope:
- Anything not operated by us — app stores, our service providers' own infrastructure (DigitalOcean, Stripe, RevenueCat, PostHog), and third-party Clients built on our public API (report those to their developer);
- Findings that are not security vulnerabilities: missing "best-practice" headers with no demonstrated impact, software version disclosure alone, self-XSS requiring a victim to attack themselves, and reports from automated scanners with no analysis;
- Volumetric denial-of-service, spam, and social engineering (see § 3 — these are never authorised);
- Physical attacks against people, property, or data centres.
If you are unsure whether something is in scope, ask first at the address in § 2.
2. How to report
Email security@iron-forge.app (or, if that address is unavailable, ironforge.admin@gmail.com with "SECURITY" in the subject line). Please include, as far as you can:
- what you found and where (URL, endpoint, app screen, or component);
- steps to reproduce it — a proof of concept helps enormously;
- what you think the impact is (what could an attacker actually do?);
- how we can reach you for follow-up, and the name or handle you'd like us to credit (crediting is optional and only ever with your consent).
Please report in confidence and give us a reasonable opportunity to fix the issue before you publish anything (see § 5).
3. The rules — what good-faith research means
Your research is authorised under this Policy only if you:
- Do no harm to real people or their data. Test only against accounts you created and control. Never access, copy, modify, or delete another person's data. If a vulnerability exposes someone else's data, stop at the minimum needed to demonstrate the issue, capture nothing beyond that proof, report it immediately, and securely delete anything you did receive.
- Don't degrade the Service. No volumetric denial-of-service, load testing, or resource exhaustion; nothing that knowingly interrupts other users' training.
- Don't use social engineering, phishing, or physical intrusion against us, our users, or our providers — those are never in scope.
- Don't move laterally. If you gain unexpected access (a server, a database, another tenant's workspace), demonstrate and report — do not explore, escalate, or persist.
- Make no demands. Reporting conditioned on payment is extortion, not disclosure; it takes you outside this Policy entirely.
- Comply with the law. This Policy authorises what we can authorise — our own systems. It cannot and does not authorise anything against systems or data that are not ours.
4. What you can expect from us
- Acknowledgement within 72 hours of your report reaching the § 2 address.
- An assessment and a plan — we'll tell you whether we can reproduce the issue, how serious we judge it, and roughly when a fix will ship. Serious, exploitable issues take priority over everything else we're building.
- A fix at no cost to anyone — security updates to the Service and the App are always free, and ship automatically where the platform supports it.
- Updates until it's resolved, and a heads-up when the fix is live so you can verify it.
- Credit, if you want it, once the issue is fixed — with your consent, never without.
- Our own reporting duties honoured. Where the law requires us to notify a regulator or affected users of a vulnerability or incident (for example under UK GDPR or, for the App on the EU market, the EU Cyber Resilience Act), we do that on the statutory timelines — your report helps us meet them, and we won't name you in any regulatory notification without your consent.
5. Safe harbour
If you make a good-faith effort to follow this Policy, then to the fullest extent of our power:
- we will not bring or support any legal action against you for your research — including under the Computer Misuse Act 1990 (UK), the Computer Fraud and Abuse Act or DMCA § 1201 (US), or their equivalents — and we waive any claim we might have for breach of the Terms of Service or Acceptable Use Policy arising from in-scope, in-rules research;
- we will consider your research authorised for the purposes of any law that turns on authorisation;
- if a third party brings an action against you for research this Policy authorised, we will make it known that your research was conducted under this Policy.
This safe harbour cannot bind third parties or prosecutors, and it does not apply to research that breaks the § 3 rules — in particular anything that harms real users or their data.
6. Coordinated disclosure
We ask for a coordinated disclosure window of 90 days from your report (or longer by agreement if a fix is genuinely complex; shorter if we ship the fix sooner). After the fix is live — or the window lapses without good cause on our side — you are welcome to publish your findings; we'd appreciate seeing the text first, purely to check no user data or unfixed issue is exposed. We publish significant fixed vulnerabilities ourselves where users need to know or act.
7. No bounty
We do not run a paid bug-bounty programme, and this Policy creates no entitlement to payment. We may, entirely at our discretion, thank a researcher whose report materially helped (for example with complimentary subscription time) — the same goodwill basis as feature requests under the Terms of Service § 10.
8. Changes
We may update this Policy as the Service grows or the law changes; the version and date above will change when we do. Research conducted under the version in force when you started it keeps that version's protection.
Vulnerability reports: security@iron-forge.app (fallback: ironforge.admin@gmail.com, subject "SECURITY"). Anything else: ironforge.admin@gmail.com.