Vulnerability Disclosure
Coordinated disclosure and security research
Last updated June 20, 2026
We welcome good-faith security research and responsible disclosure. This page describes how to report vulnerabilities in foretale.ai and what you can expect from us.
Scope
In scope for reporting:
- foretale.ai web application (app and authenticated areas).
- Public API endpoints at gateway.foretale.net and api.foretale.net.
- Authentication flows managed by Amazon Cognito for foretale.ai.
Out of scope
The following are generally out of scope:
- Social engineering, phishing, or physical attacks.
- Denial-of-service or load testing without prior written approval.
- Issues in third-party services outside our control.
- Findings from automated scanners without demonstrated impact.
- Missing security headers or cookies without exploitable impact.
How to report
Email contact@hexango.com with a detailed description, steps to reproduce, potential impact, and any proof-of-concept. Encrypt sensitive details if needed — request our PGP key in your initial message.
Safe harbor
We will not pursue legal action against researchers who act in good faith, avoid privacy violations and service disruption, do not access data belonging to others, and give us reasonable time to remediate before public disclosure.
Our commitment
Upon receiving a valid report, we aim to:
- Acknowledge receipt within 3 business days.
- Provide an initial assessment within 10 business days.
- Keep you informed of remediation progress.
- Credit researchers upon request after fix deployment (unless you prefer anonymity).
Security contact
For vulnerabilities, incidents, or security questions:
contact@hexango.com