Security · Responsible disclosure
Found a security issue? Tell us privately.
Email hello@foxora.ai with the subject “Security report”. We aim to acknowledge every report within 3 business days, and we won't take legal action over good-faith research that follows this policy.
Fig. 01 · A report, sent privately
Not public- To
- hello@foxora.ai
- Subject
- Security report
- What and whereThe web address, or the Studio version and operating system
- StepsHow to reproduce it, one step at a time
- ImpactWhat an attacker could do with it
- ContactAn email or handle we can reply to
How to report
Three steps, all of them private.
A short report with steps we can follow helps us more than a long one.
-
01 · Send
Email us the details
Write to hello@foxora.ai with the subject “Security report”, and cover the four lines on the report above.
-
02 · Hear back
We acknowledge it
We aim to acknowledge every report within 3 business days. Then we tell you whether we could reproduce it, and keep you updated while we fix it.
-
03 · Disclose together
Keep it private until it's fixed
Please don't share the issue publicly until we have fixed it and agreed a disclosure date with you. Leave other people's personal data out of your report. If you came across some, tell us and delete your copy.
Scope
What to test, and what not to.
Test Foxora's own products and sites, and leave everything else alone.
In scope · Foxora's own products and sites
- Foxora Studio web appapp.foxora.ai
- Accounts and sign-upaccount.foxora.ai
- Studio desktop apps and the Studio CLImacOS, Windows and Linux, in the latest release of each
- Our websiteswww.foxora.ai
Not sure? Ask before you test.Ask us first
Out of scope · Please don't
- Denial-of-service, load or stress testing
- Phishing, social engineering or physical attackson our team or our users
- Testing that sends messagesto people who didn't agree to it
- Automated scanner outputwith no working proof of impact
- Missing headers or best-practice settingswith no way to exploit them
- Services run by other companiessuch as payment, sign-in, hosting and model providers. Report those to the vendor, and tell us if the problem is in how we set them up.
Safe harbour
Good-faith research is welcome here.
If you make a good-faith effort to follow this policy, we will treat your research as authorised. We won't take or support legal action against you for it, and we will work with you to understand and fix the issue.
This policy can't give permission on behalf of other companies, and it doesn't cover anything that breaks the law.
Good faith means you
- 01Test only your own accounts, or accounts whose owner has given you permission.
- 02Don't access, change, keep or delete data that isn't yours, and stop as soon as you reach any.
- 03Don't disrupt the service for anyone else.
- 04Give us reasonable time to fix the issue before you tell anyone.
- 05Don't ask for payment in return for keeping an issue private.
How Studio protects your work
The controls, as they stand today.
What Foxora Studio does today, in plain words, and the standard or status each control rests on.
| Control | What it does today | Rests on |
|---|---|---|
| Sign-in | Signing in to Foxora uses a published sign-in standard, not a login we invented ourselves. | OAuth 2.0 with PKCE |
| Where work runs | Studio runs your jobs in Foxora's cloud. Your prompts and files go to Foxora and to the model providers that do the work. We don't sell your data, and our contracted model providers don't train on it. | Foxora cloud |
| Approvals | Agents ask before going past the brief you gave them, and wait for a person's yes. | Live |
| Credit budgets and ceilings | Give a job a budget, and the work stops at the ceiling. | Live |
| Connected apps | Integrations with your other apps run through one connector service, not a separate build for each app. | Composio |
Report an issue
Tell us first. We'll take it from there.
hello@foxora.ai, with the subject “Security report”.