Boards on Fire Responsible Disclosure

At Boards on Fire, we prioritize the security and privacy of our customers. We take all security vulnerabilities seriously and are committed to addressing any issues promptly and transparently. This page outlines our policy for the responsible disclosure of security vulnerabilities.

Report a Vulnerability

If you believe you have discovered a security vulnerability in any of our products or services, we encourage you to disclose it to us responsibly. Please follow the guidelines below when reporting vulnerabilities:

  1. Do not publicly disclose the vulnerability before we have had a reasonable opportunity to address it.
  2. Provide detailed information about the vulnerability, including the type of issue, affected systems, potential impact, and steps to reproduce the vulnerability.
  3. Use our dedicated reporting channel for submitting vulnerabilities to ensure that they are promptly reviewed by our security team.

How to Report

Please report security vulnerabilities by sending an email to support@boardsonfire.com, preferably delivered encrypted with Boards on Fire PGP key.

Fingerprint: 00F3 9EF2 CB7F 9094 1E4A 6CB8 D2EF E09B E16D 5616

Include the following information in your report:

  • A description of the vulnerability
  • Steps to reproduce the issue
  • Any relevant screenshots or proof-of-concept code
  • Your contact information

Scope

In-scope: *.boardsonfireapp.com

Out-of-scope: *.boardsonfire.com

Recognition and Rewards

Now we do not offer any reward for found vulnerabilities. However, if we get the feeling, we will definitely send you some of our fancy merch!

Conclusion

Boards on Fire value the security research community and believe that responsible disclosure of security vulnerabilities helps us ensure the safety and integrity of our systems. Thank you for helping us protect our customers and maintain their trust.

If you have any questions about this policy, please contact us at support@boardsonfire.com.