Do not publish a suspected vulnerability, credential, personal information, or protected technical detail in a public issue, discussion, or social post.
Systems covered by this route
This reporting route covers the Altifigence public website, account sign-in surfaces, protected-download routes, released desktop applications, and other first-party services that clearly identify Altifigence as the operator. A report may still be routed elsewhere after ownership is confirmed.
Third-party products and services are outside this policy unless the issue is caused by an Altifigence integration. Report a problem in a third-party service to that provider as well when appropriate.
How to report
Email the affected URL or product and version, impact, concise reproduction steps, supporting evidence that does not expose unrelated data, and a safe contact address to security@altifigence.com. The machine-readable contact record is available at security.txt.
Research and reporting rules
- Use only accounts, projects, systems, and data that you own or are expressly authorized to test.
- Do not access, copy, change, retain, or disclose another person's data, credentials, secrets, or content.
- Do not perform denial-of-service activity, social engineering, physical attacks, destructive testing, persistence, or activity that degrades service for others.
- Stop when the minimum evidence needed to explain the issue has been collected, and ask before testing if the authorization boundary is unclear.
Report handling
Altifigence reviews reports, may request clarification, and may coordinate validation, remediation, and disclosure with the reporter. This public page does not promise an acknowledgement or remediation deadline, reward, or eligibility for a bounty.
Coordinated disclosure
Do not disclose an unresolved report without written coordination. Altifigence may decline or end coordination for reports that are out of scope, unverifiable, abusive, duplicated, already known, or submitted in violation of these rules.
Report data
Report content and contact details are used to investigate, communicate, preserve a security record, and meet legal obligations. Avoid including personal or confidential data that is not necessary. Additional handling information appears in the Privacy Notice.
No expanded authorization or security guarantee
This policy does not grant access to a system, waive applicable law or third-party rights, promise safe-harbor treatment, or state that any service is free of vulnerabilities. Written authorization is required before any activity outside the limited rules above.
Security contact
Send suspected vulnerabilities and security-policy questions to security@altifigence.com.