Include the affected page or endpoint, what you observed, the steps needed to reproduce it, and the potential impact.
Report a security concern safely.
Use this page for a suspected vulnerability or security issue involving Folvern. Reports are reviewed manually during Founder Beta.
Do not include passwords, recovery keys, payment credentials, unrelated customer records, or secrets that are not necessary to explain the issue.
Do not scan, probe, run credential attacks, test cross-tenant access, social-engineer users, or perform denial-of-service testing without written authorization.
Security report
Your report is recorded for manual review. Folvern does not currently operate a public bug bounty or publish a guaranteed response-time SLA.
- Use plain text and a minimal reproducible description
- Do not include credentials or unrelated customer data
- Do not perform additional testing after discovering the issue unless authorized
- Submitting a report does not create permission to continue testing
Security reports are welcome. Unauthorized testing is not.
Folvern reviews submitted reports manually during Founder Beta. Any future safe-harbor terms, bounty program, or expanded disclosure policy will be published only after legal and security review.