Responsible Vulnerability Disclosure Program (VDP)
We believe responsible disclosure is vital to a safe internet. If you are an independent security researcher and discover a vulnerability in our application, we encourage you to report it to us immediately.
If you conduct your research in good faith, avoid violating the privacy of other users, do not disrupt platform availability, and give us reasonable time to resolve the issue before public disclosure, FanVault will not pursue legal action against you or seek law enforcement intervention.
Scope & Boundaries
getfanvault.comand primary web application- Authentication bypasses & privilege escalation
- SQL injection & data exfiltration risks
- Stored or reflected Cross-Site Scripting (XSS)
- Stripe webhook signature bypasses
- Unauthenticated access to sealed letters
- Volumetric Denial of Service (DDoS) attacks
- Spamming or automated brute-forcing
- Social engineering or phishing of staff
- Third-party services (e.g. Stripe, AWS endpoints)
- Missing DNSSEC or cosmetic HTTP headers without exploit
How to Submit a Security Report
Please submit all vulnerability disclosures directly to our Security Operations Team at security@getfanvault.com.
Researcher Hall of Fame
We publicly acknowledge researchers who responsibly disclose verified security vulnerabilities: