Responsible Disclosure
Last Updated: May 14, 2026
Frankee values the security research community and welcomes good-faith efforts to identify and report vulnerabilities. This page describes how to disclose security issues and what you can expect from us.
What to Report
Please report any security vulnerability that could affect:
- The confidentiality, integrity, or availability of customer data
- Authentication, authorization, or access controls
- Cryptographic implementations
- Injection vulnerabilities (SQL, XSS, command injection, etc.)
- Server-side request forgery or insecure deserialization
- Sensitive data exposure
- Misconfigured infrastructure or third-party services
If you are unsure whether an issue qualifies, please report it anyway. We will review every report submitted in good faith.
How to Report
Send your report to security@frankee.ai.
Please include:
- A clear description of the vulnerability
- Steps to reproduce the issue
- Potential impact and affected component
- Your name or handle (optional, for acknowledgment)
- Any supporting evidence (screenshots, proof of concept, logs)
What to Expect From Us
- Acknowledgment within 24 hours of receiving your report
- Initial assessment within 5 business days confirming whether the issue is reproducible and in scope
- Status updates during remediation, with timelines appropriate to severity
- Notification when the issue is resolved, including a summary of remediation steps
- Acknowledgment of your contribution (if you wish to be named) when we disclose the resolved issue
Safe Harbor
We will not pursue legal action against security researchers who:
- Make a good-faith effort to comply with this policy
- Avoid privacy violations, data destruction, and disruption to other users
- Do not exploit a vulnerability beyond what is necessary to demonstrate the issue
- Provide us with reasonable time to remediate before public disclosure
Out of Scope
The following are generally considered out of scope:
- Social engineering attacks against Frankee employees, partners, or customers
- Physical attacks against our infrastructure or personnel
- Denial-of-service attacks
- Reports from automated tools without reproducible proof of impact
- Issues in third-party services (please report directly to the service provider)
- Vulnerabilities in unsupported browsers or end-of-life software
- Self-XSS or other issues requiring victim self-targeting
- Missing security headers without demonstrable exploitability
Coordinated Disclosure
We ask that researchers refrain from publicly disclosing vulnerabilities until we have had an opportunity to remediate. We will work with you in good faith on a coordinated disclosure timeline.
Contact
Security reports: security@frankee.ai
- General support: support@frankee.ai
- Privacy inquiries: privacy@frankee.ai