BLACKFORGE
private beta

Version 1 This document is under legal review and may change.

Security and Vulnerability Disclosure

Effective September 4, 2026 · Version 1

BlackForge is a small private beta run by a small team. If you find a security problem in it, we want to hear about it, we will take it seriously, and we will treat you fairly for telling us. This page says how to report, what happens next, what we ask you not to do, and the protection you have when you follow it.

Contents

  1. How to report
  2. What to expect from us
  3. What we ask you not to do
  4. Safe harbor for good-faith research
  5. What is in scope
  6. Rewards
  7. Contact

1. How to report

Email privacy@blackforge.io with "Security report" in the subject. Please do not use the in-app feedback panel for security reports; it is read by the whole team and is not the right place for something sensitive.

A useful report includes:

Please do not include other people's personal data in a report. If you need to show us that data was reachable, describe how and we will confirm it ourselves. If you need to send something encrypted, say so in a first email and we will arrange a key.

The machine-readable version of this page is at /.well-known/security.txt.

2. What to expect from us

SeverityExamplesFix target
CriticalAnother user's private data is readable; an account can be taken over; a server secret is exposed7 days
HighSign-in or permission checks can be bypassed; content can be changed by someone who should not be able to30 days
MediumA weakness that needs unusual conditions or user interaction to exploit90 days
LowHardening gaps with no demonstrated impactNext scheduled release

3. What we ask you not to do

Research that follows these rules is welcome. Please:

4. Safe harbor for good-faith research

If you make a good-faith effort to follow this page, we consider your research authorized. That means:

  • we will not pursue or support legal action against you for it, including under computer-misuse and anti-circumvention laws;
  • we treat it as compliant with our Terms of Service, so the clause in the Terms about probing the service for weaknesses without permission does not apply to research done under this page: this page is that permission;
  • if a third party raises a legal claim about your research, we will make it clear that it was authorized by us; and
  • we will work with you to understand and fix the issue quickly.

This protection covers research done in accordance with this page. It cannot cover the rules of other companies, and it does not apply to conduct that goes beyond what this page allows. If you are unsure whether something is in bounds, ask first.

5. What is in scope

In scope

Out of scope

6. Rewards

BlackForge does not run a bug bounty and does not pay for reports. If you want, we will thank you by name (or handle) on this page once the issue is fixed.

7. Contact

Security reports and questions about this page: privacy@blackforge.io.