We want to hear about security vulnerabilities in our services. This policy says how to report one, what is in scope, what we ask of you while you look, and what we promise in return.
How to report
Email security@ironfang.com. If you cannot use email, use the contact form and say that it is a security report. English is preferred.
A useful report includes:
- the product, page or API endpoint affected;
- the steps to reproduce it, with any request ids;
- what an attacker could do with it;
- how you would like to be credited, if at all.
Leave out other people's personal data, passwords and API keys. If you had to see any to find the issue, tell us that rather than sending it.
Scope
In scope:
- ironfang.com and the subdomains Ironfang operates, including api.ironfang.com, portal.ironfang.com, id.ironfang.com and mcp.ironfang.com;
- Ironfang Render, Ironfang Finance, Ironfang Audit, Ironfang Rig and Ironfang Analytics, and their APIs;
- the SDKs, command-line tools and integrations Ironfang publishes.
Out of scope:
- services run by others that we use, such as Stripe, Cloudflare and Google, unless the issue is in how we use them;
- denial of service, and load or volume testing;
- social engineering, phishing and physical attacks;
- findings from automated scanners, and missing headers or settings, without a demonstrated impact.
While you test
- Use only your own account and your own data. Create test accounts if you need more than one.
- Do not access, change or delete data that is not yours. If you reach it, stop, keep no copy and tell us.
- Do not degrade the service for other customers.
- Point our products only at systems you own or are allowed to test. Asking Ironfang Render or Ironfang Audit to fetch someone else's systems in order to probe them breaches the Acceptable Use Policy.
- Usage while you test is billed like any other usage; the free allowances are usually enough.
- Keep the details private until we have fixed the issue or 90 days have passed since your report, whichever comes first, unless we agree otherwise.
What we promise
- We acknowledge your report within 5 working days.
- Within 10 working days we tell you whether we can reproduce it and what we plan to do.
- We keep you informed until it is fixed, and tell you when it is.
- Once it is fixed, we credit you by the name or handle you choose, if you want credit.
We do not run a bug bounty and do not pay for reports.
Safe harbour
If you make a good-faith effort to follow this policy, we consider your research authorised, including for the purposes of the Computer Misuse Act 1990, and we will not take legal action against you or report you to the police for it. If someone else takes legal action against you for research that followed this policy, we will make it known that it was authorised. This does not cover anything beyond what was needed to show the vulnerability.

