
Reporting vulnerabilities
Note: This article is for security researchers only. If you are a Front customer with questions about security, contact Front support.
Data security is Front’s top priority, and Front believes that working with skilled security researchers can identify weaknesses in any technology. If you believe you've found a security vulnerability in Front’s service or one of its apps, please notify us; we will work with you to resolve the issue promptly.
Disclosure policy
- Let us know as soon as possible when you’ve discovered a potential vulnerability by emailing us at security@frontapp.com. We vow to acknowledge your email within 24 hours.
- Provide us a reasonable amount of time to resolve the issue before disclosing it to the public or a third party. We aim to resolve critical issues within one week of disclosure.
- Make a good faith effort to avoid violating privacy, destroying data, or interrupting or degrading the Front service. Please only interact with accounts you own or for which you have explicit permission from the account holder.
Exclusions
While researching, we’d like you to refrain from:
- Testing https://frontapp.com, as this is just our marketing site
- Denial of service
- Spamming
- Social engineering or phishing of FrontApp employees or contractors
- Any attacks against Front’s physical property or data centers
Thank you for helping to keep Front and our users safe!
Changes to these guidelines
We may revise these guidelines from time to time. The most current version of the guidelines will be available in our knowledge base.
Contact
Front is always open to feedback, questions, and suggestions. If you would like to talk to us, please feel free to email us at support@frontapp.com or follow us on Twitter at @FrontApp.