Report it safely. We will respond and coordinate.
We welcome coordinated disclosure from security researchers. This policy sets out scope, safe harbor and how to reach us. A machine-readable security.txt is published under /.well-known.
Email security@fidwyn.com with steps to reproduce, affected version and impact. PGP is available on request. We acknowledge within two business days.
Good-faith research conducted under this policy will not be pursued legally. Do not access data that is not yours, degrade service, or disclose publicly before coordination.
The Fidwyn product (appliance, EPM agent, APIs) and this website. Social engineering, physical attacks and third-party services are out of scope.
We aim to triage within five business days and coordinate a disclosure timeline with you, publishing a numbered FSA advisory on fix.
/.well-known/security.txt. Contact: security@fidwyn.com. Preferred languages: EN, TR.See something? Tell us.
Coordinated disclosure protects customers and researchers alike.
