中文翻譯僅供參考
這份繁體中文版是為了讓你閱讀更順暢而準備的。如果中英文版本有任何出入,一律以英文原版為準。有任何問題,隨時 聯絡我們。
Vulnerability disclosure policy
Coordinated disclosure
Factory Labs welcomes good-faith vulnerability reports against any of our properties. Below is exactly what you can test, how to report, what you can expect from us, and the safe-harbor protection that covers your research.
Scope
All of the following are in scope. If you are unsure whether a target is in scope, email security@factorylabs.ai before testing.
In scope
factorylabs.aiand all*.factorylabs.aisubdomains, including the marketing site, Trust Center, docs, and the customer app shell.- The public CRM Factory product accessible after sign-in (any tenant you legitimately own or have written permission to test).
- Public APIs under
/api/v1/*and/api/public/*. - Mobile web clients and any first-party SDK published by Factory Labs.
- Authentication, multi-tenancy and authorization logic. Bugs that allow cross-tenant access are top priority.
Out of scope
- Third-party SaaS we use (Vercel, Neon, Twilio, Resend, Anthropic, OpenAI, Deepgram, Stripe, …). Report those to the vendor; we're happy to triage on your behalf.
- Volumetric DoS / DDoS, brute force, traffic flooding.
- Social engineering, phishing of staff or customers, physical attacks.
- Missing security headers, weak TLS ciphers, or other cosmetic findings already mitigated by configuration unless you can demonstrate exploitability.
- Self-XSS, clickjacking on pages without sensitive actions, login/forgot-password username enumeration on endpoints that already rate-limit.
- Reports from automated scanners without manual validation.
Rules of engagement
- Don't access data you don't own. If you find a cross-tenant or privilege-escalation bug, stop at proof-of-concept. Do not enumerate other tenants' records.
- No destructive testing. No data exfiltration beyond what's needed to demonstrate impact, no creating durable footholds, no deletion or modification of data.
- Use your own test tenant. Sign up for a free trial and test there. If a bug requires upgrading to a paid plan, email us first and we'll provision a sandbox tenant.
- Keep it private. Don't disclose publicly until we've had a fair chance to fix. See “Disclosure timeline” below.
- Use the official channel. Send reports to security@factorylabs.ai. Do not file public GitHub issues, tweet about unpatched bugs, or DM the founders.
What you can expect from us
| Stage | Target | What happens |
|---|---|---|
| Acknowledgment | ≤ 1 business day | A human (not an autoresponder) confirms we received your report. |
| Triage decision | ≤ 5 business days | We tell you the severity rating (Critical / High / Medium / Low) and whether the report is accepted. |
| Fix: Critical | ≤ 7 days | Cross-tenant, RCE, full account takeover, or PII exfiltration. Hot-patched on production. |
| Fix: High | ≤ 30 days | Authenticated privilege escalation, sensitive data exposure, auth bypass on narrow paths. |
| Fix: Medium / Low | ≤ 90 days | Bundled into the next scheduled hardening cycle. |
| Public disclosure | 90 days from triage | If the fix is shipped, we'll credit you here (with your permission). If not, we'll explain why and request an extension. |
Safe harbor
When you act in good faith and follow this policy, Factory Labs will:
- Not initiate legal action against you, including under the Computer Fraud and Abuse Act (CFAA), DMCA §1201, or anti-circumvention claims.
- Consider your testing activity authorized access for the purposes of computer-fraud and similar statutes.
- Work with you, not against you, including helping navigate any third-party platform whose terms might otherwise be implicated.
If at any point you're uncertain whether a particular piece of research is covered, email us first at security@factorylabs.ai and we'll respond before you proceed. This safe-harbor language is adapted from disclose.io.
How to report
Send an email to security@factorylabs.ai with the following:
- Summary: one-line description of the issue and worst-case impact.
- Reproduction steps: ordered list, ideally with cURL commands, request IDs or video. Include the test tenant slug.
- Affected URL(s) / API endpoint(s).
- Suggested severity: your own rating; we'll re-triage.
- Disclosure preference: whether you want credit, want to remain anonymous, or are planning a public write-up (and when).
PGP-encrypted reports are accepted. Fetch our public key at /.well-known/security.txt and reach out if you need a signed PGP key file.
Acknowledgments
Researchers who help us improve our security posture in line with this policy will be credited below (with permission). We're a young company. Be the first.
No public disclosures yet. Submit yours and we'll add you here.
Policy version 1.0 · Last updated May 10, 2026 · Factory Labs Inc., 8 The Green Ste B, Dover, DE 19901