Trust center

Security and vulnerability reporting

How to report a security issue in NorthFirn's website or services, and what good-faith researchers can expect in return.

What this policy covers

This policy applies to the public NorthFirn website and the online services NorthFirn operates directly. Third-party platforms NorthFirn relies on, such as hosting, form, analytics, scheduling, and payment providers, have their own security programs and reporting channels. If a report involves one of them, NorthFirn will help route it to the right place.

Good-faith research is welcome

NorthFirn will not pursue or support legal action against research that follows this policy, stays within the stated boundaries, and gives NorthFirn a reasonable chance to respond before any public discussion. Good-faith research means you avoid privacy violations, service disruption, and access to data that is not yours, and you stop and report as soon as you have confirmed an issue.

How to report an issue

Send reports through the contact form using the review, correction, or support topic, and mark the message clearly as a security report. Describe the issue, the steps to reproduce it, the affected page or feature, and its potential impact. Do not include live credentials, another person's data, or a working exploit against real accounts in the report.

Please avoid these actions

Some testing does more harm than good and is not authorized under this policy.

  • Accessing, changing, or downloading data that is not yours
  • Denial-of-service, load testing, or high-rate automated scanning
  • Phishing, social engineering, or physical attempts against staff or vendors
  • Spam, or posting exploit details publicly before a fix is coordinated
  • Testing that degrades the service for other visitors

What to expect from NorthFirn

NorthFirn will acknowledge a valid report, investigate, and work on a fix on a reasonable timeline, and will keep you informed as the issue is resolved. With your permission, NorthFirn is glad to credit your contribution once the issue is closed.

No paid bounty

NorthFirn does not run a paid bug-bounty program and does not offer money for reports. This is a coordinated-disclosure policy: the goal is a safe report, a timely fix, and responsible public discussion afterward.