1. Report a potential issue
Email contact@thefarios.com with the subject "Security Disclosure". Do not include customer data, credentials, exploitable secrets or unnecessary personal information in the initial message.
If sensitive technical material is necessary, ask us to agree a protected transfer method before sending it.
2. Information that helps us investigate
- A clear description of the issue and affected URL or service.
- The date and time observed, including time zone.
- Reproduction steps that avoid accessing other people's information.
- The expected and observed behaviour.
- Potential impact and any safe supporting screenshots.
- Your preferred contact details and disclosure expectations.
3. Good-faith research rules
Please avoid:
- Accessing, changing, downloading or retaining data belonging to another person or organisation.
- Denial-of-service activity, traffic flooding, malware, phishing, social engineering or physical intrusion.
- Credential attacks, destructive testing or persistence in an account or system.
- Testing customer workspaces without the customer's and FARI's written authority.
- Public disclosure before we have had a reasonable opportunity to investigate and address the issue.
Stop testing immediately if personal data, confidential business information or credentials become visible, and report what occurred without copying more data.
4. What to expect
We aim to acknowledge a credible report within five business days, assess severity, preserve relevant evidence and provide status updates where practical. Timing depends on impact, complexity, third-party involvement and the availability of a safe correction.
This policy does not create a bug bounty, employment relationship or entitlement to payment. Any recognition or reward is entirely discretionary and must be agreed in writing.
5. Scope and legal boundaries
This policy applies to systems owned or expressly controlled by FARI Technologies Ltd. Third-party services, customer-controlled systems and products merely mentioned on our website are outside scope unless we give written authority.
We will assess good-faith research in context, but this page cannot authorise conduct prohibited by law or by a third party. Privacy incidents may also be reported using the process in our Privacy Notice.
Effective and last updated: 24 August 2026.