Responsible Disclosure Policy
Filesie welcomes responsible reports of security vulnerabilities affecting filesie.com, Filesie-owned systems and services. This policy provides a safe channel for security researchers, customers and other third parties to report potential issues so Filesie can investigate and remediate them.
- Authentication or authorisation weaknesses.
- Exposure of personal, confidential or customer data.
- Remote code execution, injection, cross-site scripting or significant application vulnerabilities.
- Security misconfigurations with meaningful security impact.
- Broken access controls or privilege escalation.
- Other vulnerabilities that could reasonably compromise confidentiality, integrity or availability.
Please send a report to the security contact published by Filesie or, until a dedicated security address is published, contact Filesie through its official website support/contact channel with the subject “Responsible Disclosure”. Do not include unnecessary personal or confidential information in the initial report.
- Clear description of the vulnerability and affected asset.
- Steps to reproduce the issue.
- Proof-of-concept information where necessary to demonstrate impact.
- Potential security impact and severity assessment.
- Relevant timestamps, request IDs or screenshots where useful.
- Your preferred contact information for follow-up.
- Test only systems and accounts you are authorised to test.
- Use the minimum testing necessary to establish the issue.
- Do not access, copy, alter or delete data that is not yours.
- Do not perform denial-of-service, destructive testing, social engineering, phishing or physical intrusion.
- Do not establish persistence or install malware.
- Stop testing and notify Filesie if you encounter sensitive customer data or a serious security boundary.
- We will acknowledge credible reports within a reasonable period.
- We will investigate reports in good faith and may request additional information.
- We will take reasonable steps to remediate confirmed vulnerabilities based on severity and risk.
- We will not take legal action against good-faith researchers who follow this policy, except where required to protect users, comply with law or address malicious conduct.
- We may provide status updates where practical.
Good-faith security research performed within this policy is intended to be treated as authorised testing. This does not authorise activity that violates law, compromises third-party systems, accesses data beyond what is necessary to demonstrate the vulnerability, or continues after Filesie requests that testing stop.
Filesie asks researchers to allow a reasonable remediation period before public disclosure. If a vulnerability is actively exploited, materially affects users or requires urgent coordination, Filesie may work with the reporter on an accelerated disclosure plan.
- Spam, phishing or social-engineering reports where no Filesie vulnerability is demonstrated.
- Clickjacking on pages without sensitive actions.
- Missing security headers with no demonstrated impact.
- Self-XSS requiring the victim to execute code themselves.
- Automated scanner output without evidence of exploitable impact.
- Third-party infrastructure vulnerabilities outside Filesie’s control, although they may still be reported for awareness.
This policy describes Filesie’s operating standards and compliance approach. It is not legal advice or a jurisdiction-specific legal opinion. Electronic marketing, privacy, data protection and communications laws may apply differently depending on the recipient, sender, message, data source and jurisdiction. Appropriate local legal advice should be obtained where required.
This policy is effective as of September 24, 2026.