If you've found a security vulnerability on fastide.com, we encourage you to contact us immediately. We review legitimate reports and aim to address issues as quickly as possible. Before reporting, please review this document, including our reporting principles, reward guidelines, and non-reportable issues.

Fundamentals

If you follow the principles below when reporting a security issue to fastide.com, we will review your report in good faith.

We ask that:

  1. You give us reasonable time to review and address the issue before disclosing it publicly or sharing it with others.
  2. You do not interact with or access private accounts without the account owner's consent.
  3. You make a good-faith effort to avoid privacy violations, service disruptions, or data destruction.
  4. You do not exploit the issue for any reason, including to demonstrate further risks or access sensitive data.
  5. You comply with all applicable laws and regulations.

Security Reporting Program

We appreciate security researchers who help protect our platform by reporting vulnerabilities responsibly. Any recognition or reward is granted at Fastide's discretion, based on severity, impact, and report quality.

To potentially qualify for review, you must:

  1. Follow the fundamentals listed above.
  2. Report a valid security issue that could affect privacy, data, or platform security.
  3. Submit clear details through our security contact channel rather than contacting unrelated staff members.
  4. Disclose any accidental privacy violations or disruptions in your report.
  5. Understand that while we review good-faith reports, response time may vary depending on severity and workload.
  6. Understand that submission of a report does not guarantee public disclosure, recognition, or payment.

Rewards

Any reward or recognition is based on the severity and impact of the reported issue. Please provide clear, reproducible steps in your report. If the issue cannot be reproduced, it may not be eligible for a reward.

  1. The first valid report of a unique issue may receive priority consideration.
  2. Multiple findings caused by a single underlying issue may be treated as one report.
  3. We assess reports based on impact, exploitability, clarity, and overall report quality.
  4. Reward amounts, if any, are determined solely at our discretion.
Critical Severity

Examples may include:

  • Remote code execution
  • Command execution
  • Authentication bypass resulting in unauthorized administrative access
  • SQL injection exposing sensitive data
  • Full account compromise
High Severity

Examples may include:

  • Privilege escalation or lateral authentication bypass
  • Disclosure of sensitive internal data
  • Stored cross-site scripting affecting other users
  • Local file inclusion
  • Insecure handling of authentication tokens or cookies
Medium Severity

Examples may include:

  • Business logic flaws
  • Insecure direct object references
Low Severity

Examples may include:

  • Open redirects
  • Reflected cross-site scripting
  • Low-sensitivity information disclosure

Contact Information

📍 Address: 905 S Cecil St, Hobbs, NM 88240, USA

Phone: +1 (575) 237-2030

Email: Contact@fastide.com

🕐 Business Hours


Mon – Fri:   9:00 AM – 6:00 PM

Saturday:   10:00 AM – 4:00 PM

Sunday:  Closed