← Trust Center

Vulnerability Disclosure

Coordinated disclosure and security research

Last updated June 20, 2026

We welcome good-faith security research and responsible disclosure. This page describes how to report vulnerabilities in foretale.ai and what you can expect from us.

Scope

In scope for reporting:

  • foretale.ai web application (app and authenticated areas).
  • Public API endpoints at gateway.foretale.net and api.foretale.net.
  • Authentication flows managed by Amazon Cognito for foretale.ai.

Out of scope

The following are generally out of scope:

  • Social engineering, phishing, or physical attacks.
  • Denial-of-service or load testing without prior written approval.
  • Issues in third-party services outside our control.
  • Findings from automated scanners without demonstrated impact.
  • Missing security headers or cookies without exploitable impact.

How to report

Email contact@hexango.com with a detailed description, steps to reproduce, potential impact, and any proof-of-concept. Encrypt sensitive details if needed — request our PGP key in your initial message.

Safe harbor

We will not pursue legal action against researchers who act in good faith, avoid privacy violations and service disruption, do not access data belonging to others, and give us reasonable time to remediate before public disclosure.

Our commitment

Upon receiving a valid report, we aim to:

  • Acknowledge receipt within 3 business days.
  • Provide an initial assessment within 10 business days.
  • Keep you informed of remediation progress.
  • Credit researchers upon request after fix deployment (unless you prefer anonymity).

Security contact

For vulnerabilities, incidents, or security questions:
contact@hexango.com