Responsible Disclosure
If you find a vulnerability in fibric.io, an authorized BearScope account, or a managed surface that Fibric has explicitly authorized you to test, we want to hear from you. This policy defines that limited authorization. Public descriptions of the generalized Fibric kernel, CLI, API, SDK, connectors, or recipes do not make those reference or managed-early-access surfaces available for security testing.
Our commitment
We review credible, in-scope reports and prioritize confirmed issues according to risk. We aim to keep reporters informed and to limit disclosure of report details, subject to legal, regulatory, and operational needs. The safe harbor below applies only to research that stays within this policy's authorization boundary.
Scope
In scope only:
- fibric.io and static assets served from domains Fibric controls for that marketing site.
- BearScope application surfaces reached through app.bearscope.com, but only while using an account, tenant, and data you are authorized to use. Testing must stay within the hostnames and endpoints exposed to that authorized session and must not target underlying cloud resources or undisclosed hosts.
- A managed deployment only when Fibric has given you written authorization identifying the exact hostname, component, account or tenant, testing window, and any additional limits. If the surface belongs to a customer, that customer's authorization may also be required.
We are especially interested in authentication issues, unintended access across supported BearScope tenant boundaries, and integrity failures in supported action-record or duplicate-suppression paths. BearScope service endpoints invoked by an authorized session may be assessed only within that account's authorized scope. Fibric does not offer a general-purpose public platform API; another endpoint, hostname, source reference, connector, generalized-kernel component, CLI, or SDK is not in scope merely because it appears in public documentation or application traffic.
Out of scope: unlisted or undisclosed hosts, non-public APIs, reference-kernel components, managed surfaces without written authorization, third-party services and subprocessors we do not control, customer-configured connectors or systems, and anything listed under Out of scope below. When in doubt, obtain written authorization before testing.
How to report
Email security@fibric.io with enough detail for us to reproduce and assess the issue. A good report includes:
- A clear description of the vulnerability and its potential impact.
- Step-by-step instructions to reproduce it, including affected URLs, endpoints, or components.
- Any proof-of-concept, request/response samples, or screenshots, with sensitive data redacted.
- Your assessment of severity and how to reach you for follow-up.
Please report promptly after discovery and give us a reasonable opportunity to remediate before any public disclosure.
Safe harbor
If you make a good-faith effort to comply with this policy, test only an in-scope Fibric-controlled surface, avoid harm, and report promptly, Fibric will consider that research authorized and will not initiate or knowingly support legal action against you solely for that compliant research. This safe harbor does not authorize violations of law, access to another person's or tenant's data, testing of third-party or customer-controlled systems, or activity outside the limits above. It cannot bind customers, vendors, regulators, law enforcement, or other third parties. If a third party questions activity that Fibric determines complied with this policy, we may confirm the scope of our authorization.
What to expect
- Acknowledgement: we aim to acknowledge your report within three business days.
- Triage: we validate and assess severity, and may follow up for more detail.
- Updates: we keep you informed of progress through remediation.
- Resolution: we prioritize fixes by risk and coordinate timing with you where disclosure is involved.
Guidelines
To keep customers safe while you research, please:
- Do not exfiltrate data. Access only the minimum needed to demonstrate an issue, and never download, retain, or share data that is not yours.
- Do not disrupt the service. No denial-of-service, resource exhaustion, spam, or automated scanning that degrades availability.
- Respect tenancy and privacy. Use only accounts, tenants, and test data you are authorized to use. Do not attempt to access, modify, or correlate another tenant's or individual's data; if a response indicates unintended access, stop and report the minimum evidence needed.
- Stop and report if you encounter personal data, credentials, or another tenant's information, and delete any incidental copies.
- Keep it confidential until we have remediated and agreed on disclosure.
Recognition
We do not currently operate a paid bug-bounty program, but we are glad to acknowledge researchers who responsibly report valid, previously unknown vulnerabilities, with your permission and after a fix is in place. Let us know how you would like to be credited.
Out of scope
The following are generally not eligible under this policy:
- Reports from automated scanners without a demonstrated, exploitable impact.
- Denial-of-service, volumetric, or rate-limiting findings.
- Social engineering, phishing, or physical attacks against Fibric, its staff, or its customers.
- Missing best-practice headers or configurations with no demonstrated security impact.
- Issues in third-party services, subprocessors, or customer-configured systems we do not control.
- Generalized Fibric kernel components, non-public APIs, CLI or SDK packages, reference recipes, and managed deployments that Fibric has not explicitly authorized in writing for your test.
- Vulnerabilities requiring a compromised device, rooted environment, or outdated browser.