Security & Vulnerability Disclosure
Security is our practice, not just our product. If you believe you have found a vulnerability in a FOPS Tech website, service, or application, we want to hear from you.
How to report
Email security@fopstech.com (or contact@fopstech.com) with a description of the issue, the affected asset, and steps to reproduce. Please encrypt sensitive details on request. A machine-readable version of this contact is published at /.well-known/security.txt.
What we ask
Give us reasonable time to investigate and remediate before public disclosure. Do not access, modify, or destroy data that is not yours; do not run automated scanning that degrades service; do not use social engineering, physical attacks, or denial of service. Stay within the scope of your own test accounts and data.
What you can expect
We will acknowledge your report within three business days, keep you updated on remediation, and credit you (with your permission) once the issue is resolved. Good-faith research conducted under this policy will not be pursued or reported by us.
Scope
In scope: fopstech.com and its subdomains, and applications published by FOPS Tech, L.L.C. on the Apple App Store and Google Play. Out of scope: third-party services we do not operate, and findings that require a compromised device or account.
How we run our own stack
The site is served over HTTPS only with HSTS, a strict Content-Security-Policy, and standard hardening headers. Fonts and scripts are self-hosted — no third-party trackers. Access is least-privilege with multi-factor authentication, and the platform is monitored continuously. We apply the same DevSecOps and STIG-aligned practices to our own infrastructure that we deliver to clients.