Coordinated disclosure
Vulnerability disclosure
A clear route for good-faith security reports, with boundaries that protect people, data and service availability.
The dedicated security mailbox is not yet verified. The operational contact fallback is shown, and security.txt remains disabled.
01
How to report
Send a concise report using the contact details on Company Facts. Include the affected URL or component, the observed behavior, reproduction steps, likely impact, and a safe way to contact you. Do not include credentials, unnecessary personal data or data obtained from other people.
02
Responsible testing
- Use the minimum interaction needed to demonstrate the issue.
- Do not access, alter, retain or disclose another person’s data.
- Do not degrade availability, send high-volume traffic, use destructive payloads or establish persistence.
- Do not use social engineering, phishing, physical intrusion, denial of service or third-party systems.
- Stop and report promptly if sensitive data or an unsafe condition is encountered.
03
Scope and expectations
This process covers the public FutureOps website and clearly identified FutureOps-operated application endpoints. Third-party services, customer systems, production Drupal and infrastructure not explicitly presented as FutureOps-operated are out of scope.
FutureOps will triage good-faith reports, seek clarification where needed, and provide a reasonable update when practicable. This is not a bug-bounty programme and no payment, reward, safe-harbour promise or disclosure timeline is offered.
04
Confidentiality and disclosure
Keep the report and vulnerability confidential while FutureOps investigates. Coordinate any proposed publication in advance. FutureOps will handle reporter contact details only for triage, communication and security evidence, subject to applicable law and the Privacy notice.