Vulnerability disclosure policy

Coordinated disclosure

Factory Labs welcomes good-faith vulnerability reports against any of our properties. Below is exactly what you can test, how to report, what you can expect from us, and the safe-harbor protection that covers your research.

Report to
security@factorylabs.ai
Acknowledge
≤ 1 business day
Critical fix
≤ 7 days target
01

Scope

All of the following are in scope. If you are unsure whether a target is in scope, email security@factorylabs.ai before testing.

In scope

  • factorylabs.ai and all *.factorylabs.ai subdomains, including the marketing site, Trust Center, docs, and the customer app shell.
  • The public CRM Factory product accessible after sign-in (any tenant you legitimately own or have written permission to test).
  • Public APIs under /api/v1/* and /api/public/*.
  • Mobile web clients and any first-party SDK published by Factory Labs.
  • Authentication, multi-tenancy and authorization logic. Bugs that allow cross-tenant access are top priority.

Out of scope

  • Third-party SaaS we use (Vercel, Neon, Twilio, Resend, Anthropic, OpenAI, Deepgram, Stripe, …). Report those to the vendor; we're happy to triage on your behalf.
  • Volumetric DoS / DDoS, brute force, traffic flooding.
  • Social engineering, phishing of staff or customers, physical attacks.
  • Missing security headers, weak TLS ciphers, or other cosmetic findings already mitigated by configuration unless you can demonstrate exploitability.
  • Self-XSS, clickjacking on pages without sensitive actions, login/forgot-password username enumeration on endpoints that already rate-limit.
  • Reports from automated scanners without manual validation.
02

Rules of engagement

  • Don't access data you don't own. If you find a cross-tenant or privilege-escalation bug, stop at proof-of-concept. Do not enumerate other tenants' records.
  • No destructive testing. No data exfiltration beyond what's needed to demonstrate impact, no creating durable footholds, no deletion or modification of data.
  • Use your own test tenant. Sign up for a free trial and test there. If a bug requires upgrading to a paid plan, email us first and we'll provision a sandbox tenant.
  • Keep it private. Don't disclose publicly until we've had a fair chance to fix. See “Disclosure timeline” below.
  • Use the official channel. Send reports to security@factorylabs.ai. Do not file public GitHub issues, tweet about unpatched bugs, or DM the founders.
03

What you can expect from us

StageTargetWhat happens
Acknowledgment≤ 1 business dayA human (not an autoresponder) confirms we received your report.
Triage decision≤ 5 business daysWe tell you the severity rating (Critical / High / Medium / Low) and whether the report is accepted.
Fix: Critical≤ 7 daysCross-tenant, RCE, full account takeover, or PII exfiltration. Hot-patched on production.
Fix: High≤ 30 daysAuthenticated privilege escalation, sensitive data exposure, auth bypass on narrow paths.
Fix: Medium / Low≤ 90 daysBundled into the next scheduled hardening cycle.
Public disclosure90 days from triageIf the fix is shipped, we'll credit you here (with your permission). If not, we'll explain why and request an extension.
04

Safe harbor

When you act in good faith and follow this policy, Factory Labs will:

  • Not initiate legal action against you, including under the Computer Fraud and Abuse Act (CFAA), DMCA §1201, or anti-circumvention claims.
  • Consider your testing activity authorized access for the purposes of computer-fraud and similar statutes.
  • Work with you, not against you, including helping navigate any third-party platform whose terms might otherwise be implicated.

If at any point you're uncertain whether a particular piece of research is covered, email us first at security@factorylabs.ai and we'll respond before you proceed. This safe-harbor language is adapted from disclose.io.

05

How to report

Send an email to security@factorylabs.ai with the following:

  • Summary: one-line description of the issue and worst-case impact.
  • Reproduction steps: ordered list, ideally with cURL commands, request IDs or video. Include the test tenant slug.
  • Affected URL(s) / API endpoint(s).
  • Suggested severity: your own rating; we'll re-triage.
  • Disclosure preference: whether you want credit, want to remain anonymous, or are planning a public write-up (and when).

PGP-encrypted reports are accepted. Fetch our public key at /.well-known/security.txt and reach out if you need a signed PGP key file.

06

Acknowledgments

Researchers who help us improve our security posture in line with this policy will be credited below (with permission). We're a young company. Be the first.

No public disclosures yet. Submit yours and we'll add you here.

Policy version 1.0 · Last updated May 10, 2026 · Factory Labs Inc., 8 The Green Ste B, Dover, DE 19901