Security and vulnerability reporting
Found a security issue in FortiSafe? Write to [email protected]. We read every report and reply from the same address. There's no bug bounty programme.
Report an issueHow to report
- What happens and where: the affected address, screen or app.
- Steps to reproduce it.
- The impact you observed.
- A way to reach you so we can follow up.
You can write in English, Portuguese or Spanish.
Rules for testing
- Only use your own account.
- Don't access, change or delete other people's data. If you come across someone's data, stop and tell us.
- No denial-of-service attacks or load testing.
- No social engineering, phishing or contacting customers and staff.
- No intrusive testing of the VPN servers: they're run by an infrastructure partner, and we can't authorise testing on their systems.
- Allow time for a fix before disclosing the issue.
Having this channel and a security.txt file isn't, on its own, permission to test.
What already protects your account
- Passwordless sign-in: a 6-digit code sent by email, valid for 10 minutes, with up to 5 attempts and at most 5 codes per hour.
- The code and the session token are stored only as hashes: a database leak doesn't turn into access.
- On the web, the session lives in an HttpOnly, Secure, SameSite=Lax cookie and lasts up to 90 days.
- The VPN tunnel uses WireGuard.
- What we log, and for how long, is published on our What we log page.
What we don't have yet
- A bug bounty programme.
- A PGP key for encrypted reports.
- A published independent audit.
security.txt
The contact is also in /.well-known/security.txt, following RFC 9116, here and on api.fortisafe.net. /.well-known/security.txt