coordinated disclosure

Security & Vulnerability Disclosure

Security is our practice, not just our product. If you believe you have found a vulnerability in a FOPS Tech website, service, or application, we want to hear from you.

How to report

Email security@fopstech.com (or contact@fopstech.com) with a description of the issue, the affected asset, and steps to reproduce. Please encrypt sensitive details on request. A machine-readable version of this contact is published at /.well-known/security.txt.

What we ask

Give us reasonable time to investigate and remediate before public disclosure. Do not access, modify, or destroy data that is not yours; do not run automated scanning that degrades service; do not use social engineering, physical attacks, or denial of service. Stay within the scope of your own test accounts and data.

What you can expect

We will acknowledge your report within three business days, keep you updated on remediation, and credit you (with your permission) once the issue is resolved. Good-faith research conducted under this policy will not be pursued or reported by us.

Scope

In scope: fopstech.com and its subdomains, and applications published by FOPS Tech, L.L.C. on the Apple App Store and Google Play. Out of scope: third-party services we do not operate, and findings that require a compromised device or account.

How we run our own stack

The site is served over HTTPS only with HSTS, a strict Content-Security-Policy, and standard hardening headers. Fonts and scripts are self-hosted — no third-party trackers. Access is least-privilege with multi-factor authentication, and the platform is monitored continuously. We apply the same DevSecOps and STIG-aligned practices to our own infrastructure that we deliver to clients.

Report a security issue

We take every report seriously and respond quickly.

security@fopstech.com