foxora

Security · Responsible disclosure

Found a security issue? Tell us privately.

Email hello@foxora.ai with the subject “Security report”. We aim to acknowledge every report within 3 business days, and we won't take legal action over good-faith research that follows this policy.

Policy updated 14 Sep 2026

Fig. 01 · A report, sent privately

Not public
To
hello@foxora.ai
Subject
Security report
  1. What and whereThe web address, or the Studio version and operating system
  2. StepsHow to reproduce it, one step at a time
  3. ImpactWhat an attacker could do with it
  4. ContactAn email or handle we can reply to
Aim · acknowledged in 3 business days Private until it's fixed

How to report

Three steps, all of them private.

A short report with steps we can follow helps us more than a long one.

  1. 01 · Send

    Email us the details

    Write to hello@foxora.ai with the subject “Security report”, and cover the four lines on the report above.

  2. 02 · Hear back

    We acknowledge it

    We aim to acknowledge every report within 3 business days. Then we tell you whether we could reproduce it, and keep you updated while we fix it.

  3. 03 · Disclose together

    Keep it private until it's fixed

    Please don't share the issue publicly until we have fixed it and agreed a disclosure date with you. Leave other people's personal data out of your report. If you came across some, tell us and delete your copy.

Scope

What to test, and what not to.

Test Foxora's own products and sites, and leave everything else alone.

In scope · Foxora's own products and sites

  • Foxora Studio web appapp.foxora.ai
  • Accounts and sign-upaccount.foxora.ai
  • Studio desktop apps and the Studio CLImacOS, Windows and Linux, in the latest release of each
  • Our websiteswww.foxora.ai

Not sure? Ask before you test.Ask us first

Out of scope · Please don't

  • Denial-of-service, load or stress testing
  • Phishing, social engineering or physical attackson our team or our users
  • Testing that sends messagesto people who didn't agree to it
  • Automated scanner outputwith no working proof of impact
  • Missing headers or best-practice settingswith no way to exploit them
  • Services run by other companiessuch as payment, sign-in, hosting and model providers. Report those to the vendor, and tell us if the problem is in how we set them up.

Safe harbour

Good-faith research is welcome here.

If you make a good-faith effort to follow this policy, we will treat your research as authorised. We won't take or support legal action against you for it, and we will work with you to understand and fix the issue.

This policy can't give permission on behalf of other companies, and it doesn't cover anything that breaks the law.

Good faith means you

  1. 01Test only your own accounts, or accounts whose owner has given you permission.
  2. 02Don't access, change, keep or delete data that isn't yours, and stop as soon as you reach any.
  3. 03Don't disrupt the service for anyone else.
  4. 04Give us reasonable time to fix the issue before you tell anyone.
  5. 05Don't ask for payment in return for keeping an issue private.

How Studio protects your work

The controls, as they stand today.

What Foxora Studio does today, in plain words, and the standard or status each control rests on.

ControlWhat it does todayRests on
Sign-inSigning in to Foxora uses a published sign-in standard, not a login we invented ourselves.OAuth 2.0 with PKCE
Where work runsStudio runs your jobs in Foxora's cloud. Your prompts and files go to Foxora and to the model providers that do the work. We don't sell your data, and our contracted model providers don't train on it.Foxora cloud
ApprovalsAgents ask before going past the brief you gave them, and wait for a person's yes.Live
Credit budgets and ceilingsGive a job a budget, and the work stops at the ceiling.Live
Connected appsIntegrations with your other apps run through one connector service, not a separate build for each app.Composio

Report an issue

Tell us first. We'll take it from there.

hello@foxora.ai, with the subject “Security report”.